Why do AI chatbot projects stall at security approval?
AI chatbot projects rarely stall because of the technology. They stall at one question from leadership: "Where will our internal documents and customer data be sent?" The person proposing the project knows the chatbot will cut repetitive inquiries, but cannot give legal and security teams a specific enough answer.
"The vendor promises strong security" is not enough to approve. Approvers need to know where data is stored, who holds the keys, whether it is used to train models, and whether it can be deleted when you stop using the service. Missing any one of these usually sends the proposal back.
Where does your data go in a SaaS AI chatbot?
A SaaS chatbot built on RAG (Retrieval-Augmented Generation, which writes answers from documents it retrieves) typically handles your data in four stages:
1. **Upload:** PDF, Excel, Word files or website content are ingested and split for search.
2. **Storage:** documents and search data are stored on the service's servers.
3. **Retrieval and generation:** when a user asks a question, the system finds relevant passages and sends the question plus those passages to a large language model (LLM) to write the answer.
4. **Delivery:** the answer reaches the user through LINE or a website chat widget.
Each stage raises its own security question. Evaluating an AI chatbot means checking each stage in turn, not reading a "highly secure" line on a product page.
5 security questions to ask your vendor
These five questions follow the four stages above. You can paste them straight into an email to a vendor.
1. In which country, and on whose infrastructure, is data stored?
- Why it matters: Affects rules on cross-border transfer of personal data.
2. Who holds the keys? Can the vendor read the data?
- Why it matters: Decides who actually controls the data.
3. Is our data used to train models?
- Why it matters: Internal documents could surface elsewhere.
4. Is data encrypted in transit, and to what standard?
- Why it matters: Risk of interception.
5. What does the chatbot do when a question falls outside our documents?
- Why it matters: A confident wrong answer can cause harm, just like a leak.
Note: Question 5 is often skipped. A chatbot that confidently gets a contract term or return policy wrong is also a risk your legal team will ask about.
How does ONEBOT answer these questions?
ONEBOT is a SaaS customer support chatbot that VAON built for Japanese businesses. It answers from your PDF, Excel, Word and website content, through a LINE Official Account and a website chat widget.

ONEBOT also supports role-based access control (RBAC), so you can limit which documents each user group receives answers from. It comes with a 99.5% uptime SLA and a 2 to 4 week rollout. Pricing is a flat monthly plan (from ¥15,000 per month), with per-message overage only above the plan's conversation volume, so budgets are easier to forecast than with fully usage-based pricing.
One point needs to be clear. ONEBOT SaaS sends the question and relevant passages to an LLM over the internet to generate answers, and LINE itself runs over the internet. ONEBOT SaaS is not a system where "no data ever leaves your network."
When should you choose on-premise over SaaS?
An on-premise or closed-network deployment fits when internal rules do not allow data to travel over the internet, even encrypted. VAON builds RAG chatbots that run inside a company network as a separate development project through its [AI and automation services](/en/services/ai-automation), distinct from the ONEBOT SaaS plans.

On-premise gives you control over where data travels, but you take on operations and accept the limits of models your hardware can run. That is why VAON usually suggests a small PoC (proof of concept) to measure answer quality before you commit.
For agencies and SIers that want to offer an AI chatbot to their own clients, VAON runs an OEM program that provides ONEBOT under the partner's brand. The security questions in section 3 still apply, because the agency's clients will ask exactly the same things.
When is ONEBOT SaaS not the right fit?
ONEBOT SaaS is not the right fit in two cases:
1. Internal rules or client contracts forbid any data from going over the internet. Consider the on-premise option in section 5.
2. You need the chatbot to answer questions beyond the documents you provide. ONEBOT is designed to decline and hand over to a person, not to guess.
Architecture alone does not make a company compliant with Japan's Act on the Protection of Personal Information (APPI). It narrows how much data leaves your control, but you still need a legal review based on the data you handle.