Trust

Security you can build on

We handle your customers' conversations and contact details, so protecting that data is foundational — not an afterthought. Here's how.

Strict tenant isolation

Every business's data lives behind a mandatory tenant filter enforced at the database layer. One customer can never read or reach another customer's leads, conversations, or settings.

Encryption in transit & at rest

All traffic is served over HTTPS with HSTS. Sensitive integration secrets, like Google Calendar tokens, are encrypted at rest with AES-256-GCM.

Secure authentication

Passwords are hashed with bcrypt and never stored in plain text. Sessions are signed, HTTP-only, and expire automatically. Google sign-in uses OAuth 2.0 with PKCE.

Abuse & brute-force protection

Login, signup, and the public chat endpoint are rate-limited. The crawler blocks internal/private network targets to prevent SSRF, and all inputs are validated.

Hardened by default

Security headers (HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, a Content-Security-Policy) ship on every response. Environment secrets are never committed to source control.

Grounded, honest AI

The assistant answers only from your own website content. Retrieved context and visitor input are treated as data, not instructions, to defend against prompt injection.

Responsible disclosure

Found a vulnerability?

We appreciate the security community. If you believe you've found a security issue, please report it privately so we can fix it before it's disclosed.

security@chatrivox.com

Please include steps to reproduce. We aim to acknowledge reports within 3 business days.

Enterprise-grade security, small-business simple

No card required · Free plan forever · Live in ~3 minutes