Security is the architecture, not a checkbox.
Most vendors secure a system that generates answers live, then hope nothing slips through. Truebe removes that step entirely because there's no generation to secure.
How it holds up
Eight principles, true across both products.
Whether you run the WordPress plugin or Truebe Sovereign, the same rules apply.
✓🏠 Your data never leaves your infrastructure
The WordPress plugin stores everything in your own database. Sovereign runs on your own server. Truebe is never in the data path.
✓🔑 Your own AI key
You connect your own Claude or OpenAI key. The call runs from your server to your provider. Truebe never sees the content.
✓🔒 Encrypted at rest
Your AI key is encrypted with AES-256-GCM before storage. If encryption fails, the system refuses to save it rather than store it unprotected.
✓📋 Full audit trail
Every approved answer records who approved it and when. Sovereign adds a chain-verified export a regulator can confirm was never altered.
✓🚫 Nothing is ever generated
The AI interprets a question but never writes the answer. Every response is text your team wrote and approved in advance.
✓🛡️ Hardened against the standard attacks
Every database query is parameterized against SQL injection. Visitor input is rendered as text, never HTML, closing the door on XSS.
✓📱 Two-factor enforced on sensitive screens
Truebe verifies a maintained 2FA plugin is active on your site and locks sensitive screens until one is.
✓📝 Vendor oversight documentation on request
Reg S-P requires firms to have contractual breach-notification terms and ongoing oversight of any vendor touching client data. Truebe provides the documentation your due-diligence file needs — not just the technical controls.