
In recent years, artificial intelligence tools have become an integral part of doing business — from automated service agents, through data analysis, to content creation. But along with all the opportunities come risks that most business owners aren't aware of.
5 key security risks of using AI
1. Leaks of sensitive business information
When a business uses external AI tools such as ChatGPT or cloud services abroad, its business information — customer details, price lists, correspondence — is sent to servers outside Israel. Once the information leaves, there is no control over what happens to it.
2. Prompt Injection attacks
Hackers can exploit AI agents by feeding them malicious commands through ordinary messages. For example, a customer who writes a specially crafted WhatsApp message can try to get an AI agent to reveal internal information.
3. AI hallucinations
AI models can make up information that sounds credible but is completely wrong. An AI agent that gives a customer the wrong price or promises something the business doesn't provide can cause financial and legal damage.
4. Lack of cost transparency
AI services charge by usage (tokens), and without close monitoring costs can run away. A business that doesn't track its AI consumption may discover surprising invoices.
5. Dependence on a single provider — Vendor Lock-in
Businesses that build on a single AI platform find themselves stuck when the provider raises prices, changes its terms, or simply shuts down.
How AITermi handles each of these risks
Servers in Israel — the data doesn't leave the country
All of AITermi's infrastructure runs on Google Cloud in Israel (me-west1). Your customers' information — correspondence, lead details, documents — is physically stored in Israel and is not transferred to servers abroad. Every client gets an isolated database that only they can access.
Built-in protection against Prompt Injection
AITermi's AI agents work with a modular knowledge system. Instead of injecting all the business information into the prompt, the agent receives only the list of knowledge modules — and automatically retrieves the relevant module only when it needs it. All inputs are validated through Zod schemas, and there is a clear limit on the actions the agent can perform.
Knowledge modules — accurate answers, not inventions
Instead of letting an AI agent "guess", AITermi uses a knowledge module system (AgentKnowledge) that the business defines in advance: price list, services, opening hours, return policy. The agent retrieves real, verified information through the get_knowledge tool — it doesn't make things up.
Real-time cost tracking
Inside the AITermi CRM there is a Token Monitor screen that shows in real time: how many AI requests were sent, how much they cost in dollars and in shekels, broken down by agent and by user. The system calculates the cost according to the model (Gemini, OpenAI, Claude) — no surprises on the invoice.
Provider independence — interchangeable models
AITermi isn't locked into a single AI model. The LLM Adapter supports Gemini (2.5 Flash, 2.5 Pro), OpenAI (GPT-4o, GPT-4o Mini) and Claude (Haiku, Sonnet). If a provider raises prices or changes its terms — you switch models with a click, without changing anything in the system.
Security at the code level
Beyond the architecture, AITermi implements layers of technical protection:
Bcrypt Password Hashing — all passwords are hashed with bcrypt (cost factor 12). No password is stored as plain text
Rate Limiting — request rate limits: 5 login attempts per minute, 30 webhook messages per minute, 30 AI agent messages per hour
Zod validation — every piece of data that enters the system is strictly validated against predefined schemas
HMAC Webhook Verification — every incoming webhook from WhatsApp is verified with a digital signature (SHA-256 HMAC). Outgoing webhooks are signed with
X-CRM-SignatureIsolated database — every client gets a separate PostgreSQL database. There is no access between clients
In summary
Using AI in a business is no longer a question of "if" but of "how". Choosing a platform that takes security seriously — with servers in Israel, isolated data, and full transparency — isn't a luxury but a necessity.
At AITermi, we built the system from the ground up with security as a guiding principle, because we believe a small business deserves the same level of protection as a large organization.
Want to know how AITermi can help your business? Talk to us.

