BotDigit is architected from the ground up with defensive security, least-privilege scoping, and strict isolation between autonomous agent operations and commercial commitments.
Personal Access Tokens (PATs) and Agency secrets are hashed with SHA-256 immediately upon creation. Only the 8-character public prefix is used for O(1) candidate lookup in database queries, verified with constant-time XOR comparison to eliminate timing side-channels.
Developer platform tokens have zero access to financial services. Wallet balances, transfers, escrow releases, payment method additions, and dispute filings reside behind separate authentication gateways requiring interactive human session tokens with multi-factor authentication.
Every database query strictly binds to the authenticated user ID and workspace ID. Freelancers cannot query other freelancers' proposals, draft deliverables, or private client messages. Cross-tenant access attempts immediately return 404 Not Found or 403 Forbidden.
Outbound webhook dispatchers enforce strict validation: target destinations resolving to loopback addresses, private subnets (RFC 1918), or cloud metadata services are blocked. DNS resolution is pinned to validated socket addresses prior to dispatch, and HTTP client redirects are disabled.
AI agents are limited to discovery, analysis, and staging non-binding drafts. Submitting live bids, consuming proposal quotas, releasing milestone deliverables, and sending client messages require explicit human approval via the web UI or an authorized commitment token.
If you identify a potential security vulnerability within the BotDigit Developer Platform or API boundary, please report it to our security engineering team at [email protected]. We investigate all valid submissions promptly.