Back to projects
Customer service2026

BrookAI

A multi-tenant AI chatbot SaaS: a customer service bot that learns from a business’s own documents, plugs into any website and WhatsApp, and escalates to a human agent.

BrookAI

The project

BrookAI was born from a concrete need: companies that wanted to serve their customers outside business hours without hiring more staff. The bot answers using only the business’s own documents (RAG with pgvector and LangChain); it doesn’t make things up or hallucinate — if it doesn’t know, it says so and hands over to a human.

The architecture is multi-tenant by design: each client has its own isolated space with its documents, its history and its settings. The same production system serves many companies without any of them seeing the others’ data.

Adding it to a client’s website takes a single JavaScript snippet — no dependencies to install and no changes to the existing backend. The widget initialises with the tenant’s API key and starts answering straight away. The WhatsApp Business API integration takes the same bot to the most widely used messaging channel in the market.

The admin dashboard (React + Vite) lets clients manage documents, see the full conversation history, review which questions the bot couldn’t answer (a direct signal of which documentation is missing) and set the bot’s tone and name — all without touching code.

Stack: FastAPI · Python · Claude API (Anthropic) · LangChain · pgvector · Supabase · Vanilla JS widget · React + Vite · WhatsApp Business API. Dockerised, with CI/CD, and deployed on our own server.

BrookAI — image 1

Need something similar?

Tell us about your case: we start from what we have already built to get there faster and for less.

Related service: AI assistants and automation
Technical details

Challenges

  • →Reliable RAG: the bot must answer only with the client’s real information, without hallucinating or mixing in other tenants’ data
  • →Complete isolation between tenants — documents, vectors and conversations must be invisible across clients
  • →An embeddable JS widget that doesn’t break the host website’s styles or JavaScript
  • →WhatsApp Business API integration: Meta signature validation and session management per phone number

How we solved them

  • A tenant_id filter on every pgvector search — each RAG query only reaches that tenant’s chunks
  • Row Level Security in Supabase + hashed API keys per tenant — no way to reach other clients’ data even if the request is tampered with
  • Shadow DOM for the widget: styles and scripts fully encapsulated, zero conflicts with the host
  • A webhook endpoint with X-Hub-Signature-256 validation and conversation sessions indexed by phone number
PythonFastAPIClaude APILangChainpgvectorSupabaseJavaScriptReactViteDockerWhatsApp Business API