HolknDesign
← Back to studio
AI Concierge
Security Standard

What every Holkin Concierge ships with

True protection is foundational.
Never a secondary layer.

Every Holkin Concierge ships with real protection as standard. Most small‑business chatbots are off‑the‑shelf widgets with none of this. Here's what's included with yours, in plain English.

Prompt injection is the #1 documented security risk for AI apps OWASP, 2025; in one 316,637‑attempt study, 88% of people got a chatbot to give up a secret. Yours is built so they can't. Immersive Labs, 2024

And the industry isn't keeping up: 83% of organizations plan to deploy AI agents, but only 29% feel ready to secure them Cisco, 2026.

Standard on every build

It can't be talked into things

Never leaks your data — or its own setupIt can't be talked into revealing its instructions, your pricing logic, or anyone's information. Sensitive details stay out of its reach.
Required notices can't be rewordedIf you must display exact wording — a licence disclosure, a disclaimer — it will explain what that means, but never paraphrase, simplify or translate the notice itself.
Resistant to manipulationVisitors can't trick it into breaking character, ignoring its rules, or acting outside its job, including hidden or encoded attempts. An independent second model also screens every message before the concierge reads it, so a manipulation attempt is deflected at the door. Standard on every concierge, not an add‑on.

It tells the truth

Honest answers onlyIt answers from a knowledge base you approve: no invented prices, promises, or facts. If it doesn't know, it says so and offers to connect you.
Answers in your visitor's language, and refuses in it tooA concierge that holds a line in English and folds in French isn't secure, it's monolingual. Nine graded probes across French, Spanish and Arabic; zero failures.
Honest about what it storesAsk what it keeps about you and it tells you straight. Most chatbots get this wrong the same way: the AI itself has no memory, so it says “nothing is stored” while the system around it writes everything down.

It can't be turned against you

Spam & bot protection on every formAn invisible bot‑check, per‑visitor limits, and duplicate‑blocking keep a script from flooding your inbox with junk leads.
No runaway billsPer‑visitor limits and a hard daily ceiling. Past it, the concierge falls back to its safe canned answers instead of spending, and logs the incident for you.
It can't commit your businessBesides talking it can do exactly one thing: send you an email with a lead. It cannot quote a price, take a payment, or agree to anything. It was never given the ability.

And we can prove it

Privacy‑first data handlingWe collect only what's needed and keep as little as possible: no IP addresses stored, contact details stripped from logs. Aligned with Canadian privacy law (PIPEDA).
Tested like an attacker would — on a clockInjection, data‑extraction and abuse attempts, graded by an independent model: before launch, after every change, and on a schedule the system enforces.
We find out before you doEvery concierge is asked a real question every few minutes — not just “is the server up” — by an independent watchdog on separate infrastructure. If one stops answering properly, we’re alerted automatically, day or night.
Nothing ships uncheckedThe build refuses to deploy if a published fact has drifted from its approved source, runs a security audit before release, and after release confirms the concierge is genuinely answering. An update that would leave it quietly broken fails loudly instead of going live.
And what we deliberately don't do

Your conversations don't go to a third‑party chat analytics vendor. The usual way to get dashboards is to plug in an outside service that sees every message your customers send — which is exactly what a growing pile of privacy lawsuits is about. We build the reporting into your own deployment instead. Fewer companies touching your customers' words is a feature, and it's why we do it the harder way.

Measured against
OWASP ↗Top 10 for LLM Applications

The industry security checklist for AI apps: the risks every serious LLM product is measured against.

PIPEDA ↗Personal Information Protection & Electronic Documents Act

Canada's private‑sector privacy law, governing how your customers' information is collected and kept.

Also available

Enterprise‑grade options, for businesses that need them:

And one limitation, up front

Your data is hosted in the United States. If it has to stay in Canada, say so at the first conversation. That's a different design, not a setting we can flip.