Security · Compliance

Your customer data, never the product.

PII redaction by role across the dashboard, the AI prompt, and the audit log. Self-hosted email and password until the final phase. Daily DB backups + cross-region replicas + disk snapshots.

The leads you paid for, kept safe

You spent real money to earn that traffic. We treat it that way.

Putting a chat widget on your site means trusting us with your customers and every lead they turn into. Here is exactly what that trust buys, in plain terms.

Your data is yours

Every conversation, lead, contact, file, and recording in your workspace belongs to you. Export it any time in open formats. If you leave, you take it with you and we remove our copy on request.

We never sell your data

No data brokers. No ad networks. No reselling of your visitors, your leads, or your conversations to anyone, for any reason, ever. You pay us for software, not with your data.

We do not train public AI on your conversations

Your visitor chats and captured leads are never used to train third party or public foundation models. The AI answers from your own knowledge base and playbook, scoped to your workspace.

One workspace can never see another

Every query is scoped to your workspace and enforced by role. There is no shared pool where one customer could reach another customer’s leads. Cross workspace access requires an explicit, audit logged organization link that you control.

Real deletion, on your schedule

You set how long conversations and recordings are retained. When you delete a lead or a file, it is scrubbed, not hidden. A public data deletion form covers visitors and honours the request regardless of where they live.

Nothing hidden in the supply chain

Every third party that ever touches data is named in our privacy policy, with what it does and why. If we add one, the list changes before it goes live. No silent sub processors.

Where we stand on certifications

We build to SOC 2 and OWASP Top 10 practices today, encrypt customer credentials with a hardware backed key, and align our data handling with GDPR and CCPA. Card data is handled entirely by the payment gateway, never our servers. Formal third party certification is on our roadmap. Until a badge is earned, we do not claim it. What we will always do is show you exactly what we run, so you can verify it yourself.

Read the full privacy policy and sub processor list

For your legal and security team

Need a Data Processing Agreement for GDPR, or want to run a security review? Our DPA is ready to sign, and we answer the security questionnaire ourselves, in the same thread, not through a sales engineer pool. Found a vulnerability? Report it privately and we will respond fast.

Built for procurement

Security primitives, named and shipped.

We do not say “enterprise grade” and stop. Here is what is actually wired.

Payment credentials sealed at rest

Customer supplied Stripe and Authorize.Net keys are encrypted with AES 256 GCM under a hardware backed master key held in a dedicated secrets vault before they touch the database.

Visitor PII redaction by role

Agent role sees masked email and phone everywhere by default. OWNER and ADMIN see originals. Per agent toggle promotes individual agents. Bulk lead exports sit behind a TOTP gate.

Refresh token reuse detection

Stolen refresh tokens fail safely. The moment a revoked token is replayed, the entire session family is killed.

TOTP 2FA and recovery codes

Every agent can self enroll in RFC 6238 TOTP with single use bcrypt hashed recovery codes. Owners can force enrollment for admins on the Leads page.

ClamAV plus DLP on every upload

Magic byte sniff, image bomb dimension check, EXIF strip, antivirus scan, and PII detection in text uploads.

Threat intel on every visitor

Threat intelligence scoring runs at session creation and ticket submit. VPN, Tor, compromised servers, and high risk IPs are rejected silently. Verdicts are cached for 24h to keep cost down.

Email DKIM, SPF, and event tracking

Every customer authenticates their own sending domain. Outbound mail is DKIM signed. Delivered, opened, bounced, and spam reported events patch the message bubble in place in real time.

Append only audit log

Workspace, role, and auth state changes are recorded with actor, IP, and user agent. The actor name survives even if the agent is later removed.

GDPR and DMCA built in

A public data deletion form scrubs visitor PII on approval. The takedown form quarantines flagged attachments through the same scanner pipeline.

IP blocklist and click fraud gateway

Per workspace IP bans hide visitors and reject widget sessions. An optional ad click gateway gates Google Ads traffic before it touches your landing page.

No third party auth dependencies

Self hosted email plus bcrypt(12) plus JWT. Your sessions live in your database. There is no Clerk, Auth0, or Google OAuth surface to compromise.

Smart relay does not leak addresses

When a visitor reply is forwarded to the assignee's mailbox, From is rewritten to a per conversation alias. The visitor never learns the agent's personal email; the agent never has to expose theirs to reply.

E signature with audit grade PDF

Every signed contract and per version sign off renders a server side PDF embedding the canvas signature image, signer name plus company plus title, IP, user agent, and timestamp. Customer and project lead both receive confirmation emails on every signing event.

Employee data, scoped and audit logged

HR fields (salary, attendance, slips) are owner and admin only by default. Cross agent mailbox impersonation is allowed for owners but every access is recorded as mail.impersonate.view in the audit log. Salary slip generation runs in workspace local time, not UTC.

Multi gateway payments with creator attribution

Multiple titled Stripe or Authorize.Net gateways per workspace, each with separately encrypted credentials. Every payment carries an explicit creatorAgentId so attribution to the agent who closed the deal is unambiguous on the leaderboard.

Trust, by what we ship

The vendors and standards already wired in.

Each badge is a primitive in the running stack, not a marketing claim. We avoid certifications we haven't earned.

Google Cloud

Hosted on Google Cloud, with secrets sealed in a dedicated managed vault.

Google managed SSL

Google managed SSL on every public hostname, auto rotated.

TLSTLS 1.3 + HSTS

TLS 1.3 by default at the edge, HSTS preload across the suite.

Built to OWASP Top 10

Secure headers, CSP, parameterised SQL, throttling, audit log on every consequential action.

AES 256 GCM at rest

Customer payment credentials sealed with a hardware backed master key before they touch the database.

AStripe and Authorize.Net payments

Hosted form payments. Card data never touches our servers, only the gateway.

ClamAV antivirus

Every file upload streamed through ClamAV plus a magic byte sniff and image bomb check.

EUGDPR data deletion

Public data deletion form, scrub on approval, audit trail retained for the timeline obligation.

More questions?

We answer the security questionnaire ourselves.

Reach out and we'll respond in the same thread, not via a sales engineer pool.