RecoveryBuddy AI Security Policy
Effective Date: August 1, 2026
Last Updated: August 1, 2026
Platform Owner
Digjy LLC
19580 West Indian School Rd Ste 105 #973
Buckeye, Arizona 85396
United States
Website: https://recoverybuddy.net
Email: [email protected]
Security Policy
RecoveryBuddy AI (“RecoveryBuddy AI,” “we,” “our,” or “us”), owned and operated by Digjy LLC, is committed to protecting the confidentiality, integrity, and availability of our platform, systems, services, and the information entrusted to us.
This Security Policy describes the administrative, technical, and organizational safeguards that support the security of the RecoveryBuddy AI platform.
This Policy should be read together with our Privacy Policy, Terms of Service, HIPAA Notice, PHI Policy, AI Terms of Use, Responsible AI Policy, and other applicable legal documents.
Our Security Commitment
Security is integrated throughout the design, development, deployment, and operation of RecoveryBuddy AI.
Our security objectives include:
Protecting user information.
Protecting confidential information.
Maintaining platform availability.
Preserving data integrity.
Preventing unauthorized access.
Detecting security threats.
Responding to security incidents.
Supporting regulatory compliance.
Continuously improving our security posture.
Security is an ongoing process that evolves alongside technology and emerging threats.
Security Governance
Digjy LLC maintains internal security governance processes intended to support:
Risk management.
Security planning.
Security awareness.
Incident response.
Access management.
Vendor management.
Compliance monitoring.
Continuous improvement.
Security responsibilities are assigned to authorized personnel based on business needs and operational responsibilities.
Administrative Safeguards
RecoveryBuddy AI may implement administrative safeguards including:
Information security policies.
Workforce security procedures.
Background screening where appropriate.
Security awareness training.
Access authorization procedures.
Change management processes.
Vendor risk management.
Incident response procedures.
Business continuity planning.
Disaster recovery planning.
Security audits.
Compliance assessments.
Periodic policy reviews.
Administrative controls are periodically reviewed and updated.
Technical Safeguards
RecoveryBuddy AI employs technical safeguards designed to reduce security risks.
These safeguards may include:
Encryption in transit.
Encryption at rest where appropriate.
Secure authentication.
Password hashing.
Multi-factor authentication.
Role-based access controls.
Least-privilege access.
Secure APIs.
Secure session management.
Account lockout protections.
Login monitoring.
Device authentication.
Application security testing.
Software updates.
Vulnerability management.
Security logging.
Audit trails.
Malware protection.
Network monitoring.
Intrusion detection.
Rate limiting.
Web application protections.
Technical controls evolve as technology and security practices change.
Physical Safeguards
RecoveryBuddy AI utilizes physical security measures appropriate to the environments in which systems operate.
Depending on infrastructure providers and operational requirements, safeguards may include:
Controlled facility access.
Environmental protections.
Hardware security.
Secure equipment disposal.
Backup protection.
Visitor controls.
Monitoring systems.
Where cloud infrastructure providers are used, RecoveryBuddy AI relies on those providers to maintain appropriate physical security controls under contractual arrangements.
Access Management
Access to systems and information is limited to authorized individuals with a legitimate business need.
Security practices may include:
Unique user accounts.
Individual authentication.
Role-based permissions.
Least-privilege access.
Periodic access reviews.
Prompt removal of unnecessary access.
Administrative approval processes.
Users are responsible for protecting their login credentials.
Authentication
RecoveryBuddy AI may support authentication mechanisms including:
Username and password authentication.
Email verification.
Multi-factor authentication.
Session expiration.
Secure password storage.
Device verification.
Users are encouraged to enable available security features whenever possible.
Password Security
Users should:
Create strong passwords.
Use unique passwords.
Protect login credentials.
Avoid sharing passwords.
Update passwords when appropriate.
Notify RecoveryBuddy AI immediately if account compromise is suspected.
RecoveryBuddy AI never intentionally requests passwords through unsolicited communications.
Encryption
RecoveryBuddy AI is designed to use encryption technologies to protect information where appropriate.
Encryption may include:
HTTPS/TLS encryption for data transmitted over networks.
Encryption of stored information where appropriate.
Secure authentication tokens.
Encrypted backups where supported.
Encryption methods may evolve as industry standards change.
Artificial Intelligence Security
RecoveryBuddy AI implements security practices intended to support the safe operation of AI-powered services.
Security measures may include:
Prompt filtering.
Abuse detection.
Usage monitoring.
Rate limiting.
Output safety evaluations.
Human review where appropriate.
Security testing.
Model updates.
Threat monitoring.
AI systems remain subject to ongoing evaluation and improvement.
Network Security
RecoveryBuddy AI may utilize multiple network security technologies, including:
Firewalls.
Network segmentation.
Secure gateways.
Intrusion detection systems.
Intrusion prevention systems.
Traffic monitoring.
DDoS mitigation.
Secure VPN technologies where appropriate.
Network protections are regularly reviewed and updated.
Vulnerability Management
RecoveryBuddy AI seeks to identify and remediate security vulnerabilities through:
Security assessments.
Code reviews.
Vulnerability scanning.
Patch management.
Software updates.
Dependency monitoring.
Security testing.
Configuration reviews.
Known vulnerabilities are prioritized according to risk.
Monitoring and Logging
RecoveryBuddy AI may monitor systems to support:
Platform availability.
Security investigations.
Fraud detection.
Performance optimization.
Compliance activities.
Incident response.
Operational troubleshooting.
Logs may include:
Authentication events.
Administrative actions.
System events.
Error logs.
Security alerts.
API activity.
Audit trails.
Logs are protected and retained according to operational and legal requirements.
Incident Response
RecoveryBuddy AI maintains procedures for responding to suspected security incidents.
Incident response activities may include:
Detection.
Investigation.
Containment.
Eradication.
Recovery.
Documentation.
Notification where required by applicable law.
Post-incident review.
Continuous improvement.
Incident response procedures are periodically evaluated and updated.
Business Continuity & Disaster Recovery
RecoveryBuddy AI maintains plans designed to support continued operations during unexpected disruptions.
These plans may include:
Data backups.
System redundancy.
Disaster recovery procedures.
Recovery testing.
Infrastructure restoration.
Operational continuity planning.
Recovery objectives may vary depending on the nature of the affected services.
Third-Party Security
RecoveryBuddy AI works with third-party vendors and service providers that support platform operations.
Where appropriate, vendor relationships may include consideration of:
Security capabilities.
Privacy practices.
Contractual security obligations.
Compliance certifications.
Operational reliability.
RecoveryBuddy AI is not responsible for the independent security practices of third parties beyond applicable contractual obligations.
User Responsibilities
Users also play an important role in maintaining platform security.
Users should:
Protect account credentials.
Use secure devices.
Maintain updated software.
Enable multi-factor authentication where available.
Avoid sharing login credentials.
Report suspicious activity.
Use secure internet connections.
Protect confidential information.
Log out from shared devices.
Failure to follow reasonable security practices may increase security risks.
Reporting Security Concerns
If you believe you have identified:
A security vulnerability.
Unauthorized account access.
Suspicious activity.
Fraud.
Data exposure.
Potential abuse.
Security weaknesses.
Please promptly notify RecoveryBuddy AI at:
Email: [email protected]
We encourage responsible disclosure and will review reported concerns in accordance with our internal security procedures.
Compliance
RecoveryBuddy AI seeks to support compliance with applicable laws, contractual obligations, and recognized security practices appropriate to the services provided.
Compliance responsibilities may vary depending on:
User role.
Organization.
Jurisdiction.
Applicable regulations.
Contractual agreements.
Organizations remain responsible for their own regulatory compliance obligations.
Policy Updates
RecoveryBuddy AI may update this Security Policy from time to time to reflect:
Emerging cybersecurity threats.
Technological advancements.
Platform enhancements.
Legal requirements.
Industry best practices.
Operational improvements.
Updated versions will be posted on the RecoveryBuddy AI website with a revised Last Updated date.
Contact Information
Questions regarding this Security Policy may be directed to:
Digjy LLC
RecoveryBuddy AI
Security & Compliance Office
19580 West Indian School Rd Ste 105 #973
Buckeye, Arizona 85396
United States
Website: https://recoverybuddy.net
Security Email: [email protected]
Acknowledgment
By accessing or using RecoveryBuddy AI, you acknowledge that you have read and understood this Security Policy.
While RecoveryBuddy AI is committed to implementing reasonable administrative, technical, and organizational safeguards, no security program or technology can guarantee absolute protection against every threat. Users are expected to take reasonable precautions to protect their own accounts, devices, and information while using the Platform.
© 2026 Digjy LLC. All Rights Reserved.