# Security and AI safety — HEONIX AI

> How HEONIX AI protects client and customer data, which third parties see it, and
> the checks that stop the assistant saying what it should not. Only controls that
> are in place today are listed. Effective 27 September 2026.

**Canonical URL:** https://heonixai.in/security

## In short

- Messages travel on Meta's official WhatsApp Business Cloud API and Instagram Messaging API.
- Replies are written by an AI provider, currently Google's Gemini API, and checked in code before they are sent.
- Customer data is encrypted in transit and at rest, at HEONIX only the founder can access it, and it is deleted on request.
- This website sets no cookies and keeps anonymous daily counts: no identifier, IP address or message text. Abuse limits hold a salted hash of the IP address for up to an hour, never the address itself.

## Where data goes

<!-- vendors:begin (generated from _local/src/vendors.mjs) -->
| Party | What it receives | Why |
| --- | --- | --- |
| Meta Platforms | Every message to and from the customer | WhatsApp Business Cloud API and Instagram Messaging API, under Meta's own terms |
| Google (Gemini API) | The message content needed to write each reply | The primary AI provider: writes the assistant's replies |
| OpenAI | The same message content, only when it is used | Backup AI provider, used only if the primary fails |
| Anthropic (Claude API) | The same message content, only when it is used | Backup AI provider, used only if the others fail |
| Render | The data the engine handles, with customer details encrypted | Runs the engine and its database |
| Cloudflare | Every request to this website, and the anonymous daily counts | Hosts the website and the live demo's gateway |
| Payment provider | Billing details | Collects fees; HEONIX never stores card or bank details |
<!-- vendors:end -->

Nothing is sold. One client's data is never used to serve another client. If this
list changes, this page and the privacy policy change with it.

## How data is protected

- **Encryption.** Data is encrypted in transit. Customer phone numbers and chats are encrypted at rest with AES-256-GCM.
- **Access.** Access to client data is limited to the founder. There is no outsourced support team.
- **Separation.** Each client's data sits in its own space; one client's conversations are never used for another.
- **Retention.** Conversation data is kept while the service is active, so the assistant can recognise returning customers. Deletion requests are actioned within 30 days, and client and customer data is deleted within 90 days of an account closing, except what tax or legal rules require us to keep.
- **Breaches.** If a breach affects your data, we tell you without delay. For end-customer data the client, as Data Fiduciary, informs the people affected and the Data Protection Board of India, and we supply what it needs; for data we control, we inform them ourselves, as the DPDP Act requires.

## AI safety: checks, not just instructions

Instructions to an AI are requests. These are checks in code that run whether or
not the AI follows its instructions.

- **Emergency words are checked before the AI.** Incoming messages are checked against a list of common emergency words in Tamil, English, Thanglish and Hindi before any AI call. A match tells the patient to call 108 or go to the nearest emergency department, and alerts the clinic. It works even if the AI provider is down. A word list cannot recognise every way an emergency is written, so HELIO is not an emergency service.
- **Wrong-business replies are blocked.** A reply that claims to be a different business is refused before it is sent.
- **False action claims are blocked.** A reply that says a booking, a cancellation or an opt-out happened when it did not is refused before it is sent.
- **Treatment-safety verdicts are blocked for clinics.** When a patient has mentioned a condition, a reply that tells them a procedure or drug is safe, or unsafe, for them is refused, and the question goes to the doctor.
- **Double booking is refused by the database.** Two customers can never be booked into the same slot.
- **A person can always take over.** The clinic or agency can step into any conversation, and the assistant goes quiet.

## What we do not claim

- **No certifications.** HEONIX AI does not hold ISO 27001, SOC 2 or similar certifications. If your organisation has a security questionnaire, send it and we will answer it honestly.
- **AI is not perfect.** The assistant can misunderstand. It is built to hand over to a person when unsure, and the checks above cover the failures that matter most, not every possible mistake.
- **Not clinical software.** HELIO schedules, informs and escalates. It gives no clinical advice, and clinical responsibility stays with the clinic.
- **No ban-proof number.** Meta enforces its policies on everyone; no provider can promise a number is never restricted.

## This website

- No cookies, no advertising or tracking pixels. Anonymous daily counts: no identifier, IP address or message text is recorded. Abuse limits hold a salted hash of the IP address for up to an hour, never the address itself.
- Every file, the fonts included, is served by this website. Reading it sends nothing to a third party.
- Every page sends a Content-Security-Policy that allows only this site's own scripts, and cannot be shown inside another website's frame.
- The live demo runs through this website's own gateway: the engine's key never reaches your browser, each demo is sandboxed from real clients, and each is limited to 20 minutes and 20 messages.
- The "Request a live demo" form sends nothing to us. It opens WhatsApp with your details filled in, and nothing is sent until you press send there.
- The live demo bot sends the business details and messages you type to our engine to generate replies. Demo conversations use a placeholder number and are purged periodically.

## Report a security issue

Email haroon@heonixai.in with "Security" in the subject line. We acknowledge within
72 hours. Please do not test against a client's live WhatsApp number.

## Contact and grievance officer

| Field | Value |
| --- | --- |
| Grievance officer | Mohammed Haroon J, Founder |
| Entity | HEONIX AI, a sole proprietorship of Mohammed Haroon J, registered MSME (UDYAM-TN-03-0324205) |
| Email | haroon@heonixai.in |
| Phone | +91 63801 95623 |
| Location | Coimbatore, Tamil Nadu, India |

## More

- [Home](https://heonixai.in/)
- [Privacy policy](https://heonixai.in/privacy)
- [Terms of service](https://heonixai.in/terms)
