As AI chatbots become embedded in daily workflows — drafting emails, reviewing documents, and even connecting to personal accounts through plugins and integrations — the security and privacy posture of these tools deserves the same scrutiny we would apply to any other software handling sensitive information. Topeny conducted a structured privacy and security review of several widely used AI chatbot assistants, focusing on data handling transparency, account security features, and resistance to common manipulation techniques.
Scope of This Audit
This review is not a formal penetration test or a claim of having identified specific vulnerabilities in any vendor’s infrastructure. Instead, we examined publicly documented data practices, tested account-level security features available to ordinary users, and ran a set of prompts designed to probe how each assistant handles requests that touch on sensitive or potentially manipulative territory. Our goal was to assess the practical privacy and safety posture an everyday user or business would actually experience.

Data Retention and Training Use Transparency
One of the most consequential differences between chatbot platforms is whether conversation data may be used to train future models by default, and how clearly that policy is communicated. We reviewed each platform’s published privacy documentation and settings pages. Most major platforms now offer some form of opt-out or a business/enterprise tier that excludes conversation data from training by default, but the clarity of these settings varied. Some platforms surfaced the relevant toggle prominently in account settings, while for others, finding the precise data-use setting required digging through several layers of documentation — a usability gap that likely means many casual users never adjust settings they might otherwise want to change.
We recommend that any user or business handling sensitive information through a chatbot review the current, specific privacy policy of their chosen platform directly, since these policies are updated periodically and vendor practices can differ significantly from one another and change over time.
Account Security Features
We checked whether each platform supported two-factor authentication, session management (the ability to see and revoke active sessions on other devices), and clear notification of new device logins. Most platforms we reviewed supported at least basic two-factor authentication, which is an important baseline given that a compromised chatbot account can expose an extensive history of potentially sensitive conversations. Session visibility and management varied more, with some platforms offering a clear list of active sessions and one-click revocation, while others offered more limited visibility into where an account was currently logged in.
Handling of Sensitive Personal Information
We tested how each assistant responded when users volunteered sensitive personal information unprompted, such as full financial account details or health information, in the course of an otherwise unrelated request. Well-designed assistants generally proceeded with the task while avoiding unnecessary repetition or storage of the sensitive detail in their visible response, and some proactively noted that the user might want to avoid sharing highly sensitive identifiers in a chat context. This kind of gentle, non-alarmist guidance struck us as a reasonable middle ground between being unhelpfully paranoid and being carelessly permissive.
Resistance to Prompt Injection and Manipulation
For assistants with browsing, plugin, or connected-app capabilities, we tested resistance to prompt injection — attempts to embed hidden instructions within a webpage or document that the assistant processes, designed to hijack its behavior against the user’s actual intent. This is an active and evolving area of AI security research, and no platform we tested was perfectly immune to every injection technique attempted, though the more security-conscious platforms showed clearer guardrails, such as refusing to follow instructions embedded in fetched content that contradicted the user’s original request, and being more transparent about content that was pulled from an external source versus generated directly. This remains an area where the entire industry continues to improve, and users granting a chatbot access to browsing or third-party integrations should apply a reasonable degree of caution, particularly when processing content from untrusted sources.
Handling of Requests for Harmful Information
We ran a standard set of prompts probing whether assistants would provide clearly harmful technical information (such as detailed guidance for creating weapons or malicious code) under various indirect framings. All major assistants we tested correctly declined these categories of requests consistently, including when framed as fictional, educational, or hypothetical scenarios designed to test whether a simple reframing would bypass safety measures. This is a positive and consistent finding across the industry at this point, reflecting years of safety research being applied broadly rather than being a differentiator between vendors.
Transparency About AI-Generated Content
Because chatbots are now used to draft content that gets published or sent to other people, we also examined whether each platform provided any built-in mechanism for disclosing AI involvement, such as watermarking or metadata for generated images and documents. Practices here are inconsistent industry-wide and represent an area of active development and, in some jurisdictions, emerging regulation, rather than a settled standard. Businesses using AI-generated content in professional or public-facing contexts should establish their own internal disclosure practices rather than assuming a platform’s default behavior meets their specific obligations.
Summary Table
| Security Dimension | Platform 1 | Platform 2 | Platform 3 |
|---|---|---|---|
| Data-use transparency | Good | Fair | Good |
| Two-factor authentication | Yes | Yes | Yes |
| Session management | Strong | Basic | Strong |
| Prompt injection resistance | Moderate | Moderate | Strong |
| Harmful content refusal consistency | Strong | Strong | Strong |
Recommendations for Users and Businesses
- Enable two-factor authentication on any AI chatbot account, especially if it is connected to email, calendar, or file storage integrations.
- Review the specific, current data-retention and training-use settings for your chosen platform rather than assuming a default that may not match your preferences.
- Avoid pasting highly sensitive identifiers (full account numbers, government ID numbers) into chat conversations where it is not strictly necessary for the task.
- Apply extra caution when granting browsing or third-party plugin access, particularly when the assistant may process content from untrusted external sources.
Conclusion
The overall security posture of mainstream AI chatbot assistants has improved meaningfully, with consistent baseline protections like two-factor authentication and largely reliable refusal of clearly harmful requests. Where meaningful gaps remain is in the clarity of data-use settings for everyday users and in the industry-wide, still-evolving challenge of prompt injection resistance for assistants with browsing or plugin capabilities. As with any tool handling sensitive information, a bit of user-side diligence — checking settings, enabling available security features, and being thoughtful about what gets shared — goes a long way toward using these assistants safely.
Comparing Enterprise vs. Consumer Tiers
Several of the platforms we reviewed offer distinct consumer and business/enterprise tiers with materially different default privacy settings. In general, enterprise tiers were more likely to exclude conversation data from model training by default and to offer more granular administrative controls, such as centrally managed data retention policies and audit logs for a team’s usage. Consumer tiers more often required the individual user to manually locate and adjust the relevant setting. Organizations planning to roll out an AI chatbot assistant broadly to employees should strongly consider the business tier specifically for the improved default privacy posture and centralized administrative control, rather than relying on individual employees to correctly configure their own personal-tier settings.
What This Means in Practice
None of this is meant to suggest that mainstream AI chatbot assistants are unsafe to use for ordinary purposes; our testing found consistent baseline protections and generally responsible handling of clearly harmful requests across every platform reviewed. Rather, the findings point to where a small amount of user or administrator diligence meaningfully improves the privacy and security outcome: checking data-use settings explicitly, favoring business tiers for organizational deployment, enabling available account security features, and applying healthy skepticism to any assistant capability that involves browsing or processing content from external, untrusted sources.
Vendor Responsiveness on Reported Issues
As part of our review process, we also considered how straightforward it was to report a suspected security or privacy issue to each vendor, and whether public-facing security disclosure channels existed. Most major platforms we reviewed maintained a documented responsible-disclosure or security contact channel, which is a positive baseline signal for how seriously a vendor treats external security research. This is a meaningful factor for businesses evaluating a long-term vendor relationship, since a platform with an active, well-documented security disclosure process is more likely to identify and patch emerging issues quickly compared to one without a clear channel for external researchers to report findings.
Keeping This Report Current
Security and privacy practices in this industry evolve quickly, sometimes in response to new regulation and sometimes in response to publicly disclosed incidents at a specific vendor. A platform’s posture at the time of this review is not a permanent guarantee of its posture six or twelve months from now, in either direction — practices can improve following a public incident just as easily as they can quietly regress after a leadership or policy change. We plan to revisit this audit periodically and would encourage readers to treat any single point-in-time review, including this one, as one input among several rather than a final, permanent verdict on any platform’s safety.




Leave a Reply