Botxona

Security

When many bots share one platform, the biggest risk is one bot affecting another, or the host itself. Botxona guards against that with several layers of defense.

Container isolation

Every bot runs in its own Docker container on its own network — by default it cannot reach the internet directly, only the Telegram API through a proxy. The container runs as a non-root user, its filesystem is writable only under DATA_DIR, everything else is read-only. CPU and RAM are capped per the plan.

Encryption

The bot token, .env settings and backup files are encrypted with AES-256-GCM. The master key lives only on the server; a separate key is derived for each bot.

Analytics without personal data

Analytics only collects call counts, errors and response time — message text is never stored.

Abuse prevention

Every uploaded code goes through a security scanner. Every public bot page has a "Report" button for fraud, phishing, spam, gambling or illegal content; reports are reviewed by staff and a bot can be suspended.

Backups

An automatic backup runs every day at 03:00 Tashkent time for active bots, kept for 7–30 days depending on the plan.

Long polling, not webhooks

Bots receive Telegram updates via long polling — your bot code never opens a port to the outside world, it only reaches out to Telegram. This keeps setup simple and reduces attack surface.

More on the process: How it works. Pricing: Pricing. Questions: FAQ.