Skip to content
Security & data

Trust begins with knowing the details.

Understand the controls in the product, the choices your team makes, and the deployment information to review before rollout.

01

Access follows the workspace.

Authenticated operations use organization and website context. Workspace roles limit who can change settings, connect providers and manage content.

02

Credentials have a separate path.

Integration credentials are encrypted with AES-256-GCM using a configured server key. Secret credentials belong on the server, not in the website embed.

03

Knowledge requires review.

Published sources inform visitor answers. Drafts remain separate, and the private playground lets your team test behavior before installation.

A practical review

Ask for evidence that fits your requirements.

Application features are one part of a security review. Hosting, operations, provider agreements and retention also matter.

Authentication and team access

The product includes account authentication, team roles and Enterprise SAML SSO capabilities. Configure access around the people who need it and review membership as responsibilities change.

Visitor information and integrations

Conversations, visitor-provided contact details, published knowledge and usage records support the product workflow. Administrators choose connected tools. Review permissions and the information sent to each destination.

AI provider configuration

Answer generation uses the configured AI provider. Confirm the active provider and model, contractual terms, processing locations and data handling for your deployment. Provider availability and settings affect the service.

Retention, export and deletion

The application includes data export, organization deletion and retention tooling. Ask the operator to confirm the production schedule, backup behavior and the process for visitor data requests.

Security reviews and reporting

Contact the team for a security questionnaire, deployment details or to arrange a private vulnerability report. Start with a high-level description; avoid sending credentials or sensitive exploit details through a general sales form.

Request a security review ↗

Read the review documents.

The legal documents are clearly marked drafts while entity details, deployment facts and contractual terms await approval.