Bashy AI Security & Data Protection

Last updated: April 27, 2026

Overview

Bashy AI is designed with a security-first architecture to ensure that customer data is protected, access is controlled, and sensitive credentials are never exposed. We follow industry best practices including:

Authentication & Third-Party Access

Bashy AI integrates with platforms such as Google, Meta, and TikTok using OAuth 2.0.

Token Management via Nango

We use Nango to securely manage OAuth connections.

Data Access & Scope Control

Bashy AI only accesses data that you explicitly authorize. Typical data includes:

We do not access:

Data Minimization & PII Handling

We are intentionally designed to work with aggregated marketing data.

If PII is present in source platform data, it is:

Data Storage & Isolation

We do not replicate full third-party datasets unnecessarily.

Infrastructure & Security Controls

We implement industry-standard safeguards including:

Report Generation Safeguards

Reports generated by Bashy AI:

Customers are responsible for reviewing reports prior to external distribution.

Access Revocation & Control

You can revoke access at any time:

Once revoked:

Compliance & Governance

Bashy AI aligns with:

We continuously improve our security posture as we scale.