Is Botpress HIPAA compliant?
By Riley Park · Last verified: September 2026
Yes, on the Enterprise plan. Botpress lists HIPAA compliance and a formal Business Associate Agreement (BAA) as Enterprise features, alongside SOC 2 Type II certification, GDPR compliance, a private LLM gateway that strips PII before any model call, and zero data retention on the model provider's side. The Free, Plus, and Team plans do not include a BAA. Verified on botpress.com/enterprise and botpress.com/pricing, September 29, 2026.
What Enterprise includes that matters for PHI. Beyond the BAA itself: a private LLM gateway with PII stripping, so protected data is removed before a prompt reaches OpenAI, Anthropic, or any other model provider; zero data retention on the provider side, so the model vendor keeps nothing; audit and conversation logs; custom data retention and residency terms; an uptime SLA; and a dedicated support team. Enterprise is custom-priced and requires a sales conversation.
What the lower plans include. Free ($0), Plus ($150/mo billed annually), and Team ($750/mo billed annually) run on the same SOC 2 Type II infrastructure and are GDPR compliant, but none includes a BAA, which is the legal prerequisite for handling PHI under HIPAA. SOC 2 is a security audit, not a HIPAA instrument; a covered entity that deploys a Botpress agent on Plus or Team to handle patient data would be doing so without the required agreement.
The self-hosting route. Botpress publishes its platform under the MIT license and supports self-hosting. A self-hosted deployment on HIPAA-eligible infrastructure (with the cloud provider's own BAA) inherits that infrastructure's compliance posture, and the organization takes on every control itself. That is a legitimate path for teams with engineers, but it is not the same as Botpress being HIPAA compliant; it is the customer being compliant on their own infrastructure. For most healthcare buyers, Enterprise is the route the vendor supports.
How this compares in the category. Among the seven no-code AI agent builders DDR reviews, four vendors state a HIPAA offering with a BAA: Botpress, Lindy, and Chatbase on their Enterprise plans, and Gumloop on Pro and above per its own security page. Voiceflow states HIPAA compliance on its site, but the plan tier required could not be verified from public sources. Dify does not mention HIPAA in its compliance documentation (SOC 2, ISO 27001, and GDPR are confirmed) and offers full data control by self-hosting instead. MindStudio confirms SOC 2 and GDPR but not HIPAA. The DDR Comparison Matrix carries this row for all seven, with the tier each requires.