True protection is foundational. Never a secondary layer.
Every Holkin Concierge ships with real protection as standard. Most small‑business chatbots are off‑the‑shelf widgets with none of this. Here's what's included with yours, in plain English.
Prompt injection is the #1 documented security risk for AI apps OWASP, 2025; in one 316,637‑attempt study, 88% of people got a chatbot to give up a secret. Yours is built so they can't. Immersive Labs, 2024
And the industry isn't keeping up: 83% of organizations plan to deploy AI agents, but only 29% feel ready to secure them Cisco, 2026.
Standard on every build
It can't be talked into things
Never leaks your data — or its own setupIt can't be talked into revealing its instructions, your pricing logic, or anyone's information. Sensitive details stay out of its reach.
Required notices can't be rewordedIf you must display exact wording — a licence disclosure, a disclaimer — it will explain what that means, but never paraphrase, simplify or translate the notice itself.
Resistant to manipulationVisitors can't trick it into breaking character, ignoring its rules, or acting outside its job, including hidden or encoded attempts. An independent second model also screens every message before the concierge reads it, so a manipulation attempt is deflected at the door. Standard on every concierge, not an add‑on.
It tells the truth
Honest answers onlyIt answers from a knowledge base you approve: no invented prices, promises, or facts. If it doesn't know, it says so and offers to connect you.
Answers in your visitor's language, and refuses in it tooA concierge that holds a line in English and folds in French isn't secure, it's monolingual. Nine graded probes across French, Spanish and Arabic; zero failures.
Honest about what it storesAsk what it keeps about you and it tells you straight. Most chatbots get this wrong the same way: the AI itself has no memory, so it says “nothing is stored” while the system around it writes everything down.
It can't be turned against you
Spam & bot protection on every formAn invisible bot‑check, per‑visitor limits, and duplicate‑blocking keep a script from flooding your inbox with junk leads.
No runaway billsPer‑visitor limits and a hard daily ceiling. Past it, the concierge falls back to its safe canned answers instead of spending, and logs the incident for you.
It can't commit your businessBesides talking it can do exactly one thing: send you an email with a lead. It cannot quote a price, take a payment, or agree to anything. It was never given the ability.
And we can prove it
Privacy‑first data handlingWe collect only what's needed and keep as little as possible: no IP addresses stored, contact details stripped from logs. Aligned with Canadian privacy law (PIPEDA).
Tested like an attacker would — on a clockInjection, data‑extraction and abuse attempts, graded by an independent model: before launch, after every change, and on a schedule the system enforces.
We find out before you doEvery concierge is asked a real question every few minutes — not just “is the server up” — by an independent watchdog on separate infrastructure. If one stops answering properly, we’re alerted automatically, day or night.
Nothing ships uncheckedThe build refuses to deploy if a published fact has drifted from its approved source, runs a security audit before release, and after release confirms the concierge is genuinely answering. An update that would leave it quietly broken fails loudly instead of going live.
And what we deliberately don't do
Your conversations don't go to a third‑party chat analytics vendor. The usual
way to get dashboards is to plug in an outside service that sees every message your customers send —
which is exactly what a growing pile of privacy lawsuits is about. We build the reporting into your own
deployment instead. Fewer companies touching your customers' words is a feature, and it's why we do it
the harder way.
The industry security checklist for AI apps: the risks every serious LLM product is measured against.
PIPEDA ↗Personal Information Protection & Electronic Documents Act
Canada's private‑sector privacy law, governing how your customers' information is collected and kept.
Also available
Enterprise‑grade options, for businesses that need them:
Abuse alerting
Formal data‑retention & incident response
The written data‑handling terms your privacy obligations require you to have with a supplier. Most clients don't know to ask, which is exactly why we bring it
And one limitation, up front
Your data is hosted in the United States. If it has to stay in Canada, say
so at the first conversation. That's a different design, not a setting we can flip.