Trust

Security at Blengi

A plain account of how your content, your workspace and your visitors' conversations are kept separate, stored and reached.

The short version

Blengi answers questions using one business's own content. That content, and the conversations that come from it, belong to you. This page sets out how they are kept apart from every other customer on the platform, where they are held, and who can reach them.

There are no badges on this page and no certification claims. What follows is a description of what the platform does, and nothing beyond that.

What is in place

  • Workspace isolation. Each workspace is separated from every other one. An agent can retrieve only from the sources loaded into its own workspace.
  • EU hosting. Your content and your conversations are hosted in the EU, and the platform is built to work in line with the GDPR.
  • You choose what the agent can read. The knowledge base is built from the sources you connect: your website and sitemap, PDFs, Word files, Google Docs, Notion pages, pasted text and SQL databases. Sources are re-crawled automatically on a schedule, and a source can be re-indexed on demand when something must land now.
  • Access stays inside the workspace. Agents, knowledge sources, conversations and leads belong to the workspace they were created in. When a person takes over a live conversation, they do it from the shared inbox in that same workspace.
  • Your content is not training data for anyone else. Customer content is never used to train models for other customers.
  • A closed knowledge base. Agents answer from the sources you add, and say when they do not know, rather than drawing on the open internet.
  • Separate bases for agencies. Under an agency workspace, each client keeps its own knowledge base, presented under the agency's own brand.

Common questions

Is our content used to train AI models?Your content is the material your own agents answer from. It is never used to train models for other customers.
Where is our data held?In the EU. Hosting is in the EU, and the platform is built to be GDPR-aligned.
Can another Blengi customer see our knowledge base?No. Every workspace is isolated, and an agent can retrieve only from the sources inside its own workspace.
Does Blengi hold a security certification?We make no certification claims. If your procurement process needs specific answers on hosting, access or data handling, ask us and we will answer them directly.

Reporting a vulnerability

If you believe you have found a security problem in Blengi, tell us before you tell anyone else. Use the contact route on this site, or your usual account contact. Describe what you found and how to reproduce it, and include the URL, the request and anything else that helps us see what you saw.

Please test only against your own workspace. Do not access, change or download data that is not yours, and do not run scans that could degrade the service for live visitors. An account of your own is enough to demonstrate almost any issue.

We read every report and reply to the person who sent it. Where an issue is confirmed, we ask for reasonable time to fix it before it is made public.

If you need more detail

Security reviews rarely fit a template. The documentation is the place to start when your team wants specifics on how the platform works.

Read the documentation