Security
When many bots share one platform, the biggest risk is one bot affecting another, or the host itself. Botxona guards against that with several layers of defense.
Container isolation
Every bot runs in its own Docker container on its own network — by default it cannot reach the internet directly, only the Telegram API through a proxy. The container runs as a non-root user, its filesystem is writable only under DATA_DIR, everything else is read-only. CPU and RAM are capped per the plan.
Encryption
The bot token, .env settings and backup files are encrypted with AES-256-GCM. The master key lives only on the server; a separate key is derived for each bot.
Analytics without personal data
Analytics only collects call counts, errors and response time — message text is never stored.
Abuse prevention
Every uploaded code goes through a security scanner. Every public bot page has a "Report" button for fraud, phishing, spam, gambling or illegal content; reports are reviewed by staff and a bot can be suspended.
Backups
An automatic backup runs every day at 03:00 Tashkent time for active bots, kept for 7–30 days depending on the plan.
Long polling, not webhooks
Bots receive Telegram updates via long polling — your bot code never opens a port to the outside world, it only reaches out to Telegram. This keeps setup simple and reduces attack surface.
More on the process: How it works. Pricing: Pricing. Questions: FAQ.