Security basics #
- Tenant isolation. Every organisation's data is separated at the database level, not only in application code. A credential or session works for one organisation only.
- Least privilege. Staff roles grant only the capabilities needed for the job; sensitive actions are recorded in an audit trail.
- Separate hosts. The workspace, the machine API and this documentation run on separate hostnames. Session cookies are host-only, and there is no cross-origin API access from browsers.
- Transport and headers. HTTPS with HSTS everywhere; strict content security policies on every page; pages that need no script run none.
- Signed machine access. Server calls are authenticated and signed; webhooks are signed the same way; rate limits apply to sign-in, the API and customer chat.
- No secrets in documentation. Credentials are shown only to authorised staff in the workspace and are never part of public pages.
Messaging channels #
- Credentials for Telegram and WhatsApp are encrypted at rest and are never shown again after saving.
- Webhook verification. Incoming provider requests are accepted only with a valid secret path and the provider's signature or secret header.
- Safe media download. Files are fetched with SSRF protection, and type and size limits apply before any processing.
- No message content in logs. Operational logs do not contain customer message text.
- Isolation. Each connection is bound to one project of one organisation, enforced on the server.
See Messaging channels architecture.
Service health is published on the status page. To work with your own credentials and connections, sign in to the workspace.