Trust
Security you can build on
We handle your customers' conversations and contact details, so protecting that data is foundational — not an afterthought. Here's how.
Strict tenant isolation
Every business's data lives behind a mandatory tenant filter enforced at the database layer. One customer can never read or reach another customer's leads, conversations, or settings.
Encryption in transit & at rest
All traffic is served over HTTPS with HSTS. Sensitive integration secrets, like Google Calendar tokens, are encrypted at rest with AES-256-GCM.
Secure authentication
Passwords are hashed with bcrypt and never stored in plain text. Sessions are signed, HTTP-only, and expire automatically. Google sign-in uses OAuth 2.0 with PKCE.
Abuse & brute-force protection
Login, signup, and the public chat endpoint are rate-limited. The crawler blocks internal/private network targets to prevent SSRF, and all inputs are validated.
Hardened by default
Security headers (HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, a Content-Security-Policy) ship on every response. Environment secrets are never committed to source control.
Grounded, honest AI
The assistant answers only from your own website content. Retrieved context and visitor input are treated as data, not instructions, to defend against prompt injection.
Responsible disclosure
Found a vulnerability?
We appreciate the security community. If you believe you've found a security issue, please report it privately so we can fix it before it's disclosed.
Please include steps to reproduce. We aim to acknowledge reports within 3 business days.
Enterprise-grade security, small-business simple
No card required · Free plan forever · Live in ~3 minutes