Skip to content
Platform

Security and privacy controls

This guide describes implemented controls and where to find them in the console. Deployment settings and the legal documents determine the applicable service configuration and commitments.

Workspace scoping

The tenant console resolves workspace scope on the server from authenticated access. Services scope content, conversations and business records to the workspace, and customer actions have their own ownership checks. The repository includes isolation tests; those tests do not constitute an independent certification.

Credentials and channels

Supported channel secrets are encrypted in backend storage and masked in console responses. Follow provider verification and connection-readiness results when enabling a channel. Channel verification, webhook checks and health monitoring address different parts of the connection.

The web widget has an allowed-origin configuration and a rotatable embed key. List the intended website origins and update the snippet after rotating the key. See channels and API credentials for the relevant setup.

Accounts and access

Server authorization checks control access to protected operations. Each console area and the API behind it require a specific permission, checked on every request, so a removed role takes effect on the member’s next action. Team supports built-in and custom roles with effective permissions and assignment history; accounts without assignments keep their legacy access. Product availability, readiness and sensitive-action checks remain separate from role assignments. See what each permission opens.

Manage your password and MFA under Account. Sensitive actions can require a current MFA-authenticated session. The account page can also sign you out everywhere at once.

Forgot your password? Ask for a reset from the sign-in page and a one-time code is emailed to your sign-in address — the only place it is sent. The code expires, can be used once, and choosing a new password signs you out everywhere.

You can delete your own account from Account → Danger zone, with your password (and a current code if MFA is on) and the word DELETE. You are signed out everywhere immediately, the account cannot be restored, and its email can never be used to open another account or accept an invitation. Handoffs and requests you were holding return to your team and your unsent drafts are discarded. The last owner or administrator of a workspace that still has teammates must hand that role over first; if you are the only member left, the workspace closes with your account: the assistant stops, its subscription is set not to renew, and its data is kept until the platform removes it.

Customer membership is separate from teammate access. Settings → Customer access controls public, unlisted and private workspace visibility and the available membership-invitation flow.

Review and audit records

Channel changes, privacy operations, role assignments and supported content reviews create records in their respective tools. Knowledge and media approval can bind a reviewer to an exact revision and content hash; changed content requires renewed review where the publication boundary applies. See Knowledge review and media publication.

Audit fields and retention vary by workflow. Give a useful reason or request reference when a form asks for one, and avoid adding unnecessary customer data to the reason field.

Sensitive information

Collection checklists and response guards restrict credentials and sensitive identifiers such as card details, PINs, passwords and one-time codes. Do not ask customers to provide these through the assistant. A customer can still send unsolicited sensitive information; a guard is not a guarantee that such data can never appear in a transcript.

Some document-processing paths require security scanning before extraction. Requirements and raw-file retention depend on the enabled processing workflow. Incoming customer media, curated workspace assets and Knowledge sources have different purposes and lifecycles; do not assume one upload policy covers all three.

Privacy tooling

Authorized workspace members use Privacy to export or erase matching customer data. Verify the requester and customer identifier before acting, provide the required reason, and complete the confirmation and authentication steps shown by the form.

ExportDownload matching data and the reported record counts. Exports can contain personal information; store and share the file through your organization’s approved process.
EraseRemove the supported matching records and pending delivery data within the workspace. Review the reported scope and confirmation carefully because deletion cannot be undone through the console.
Related workflowsCommerce and appointment records participate in customer privacy handling. Relevant retention, audit exceptions and downstream-provider handling are described by the applicable policies.

A console erasure does not establish immediate deletion from every provider, backup or file somebody already exported. Consult the data deletion policy for scope and handling.

Assistant → Answer quality → Reuse & memory contains controls for quality analysis, customer memory and improvement-data retention. Permission for de-identified conversation analysis defaults to off. Individual intelligence features also depend on platform enablement.

Review sensitive content before approving it for any improvement workflow. Automated redaction does not reliably remove every name, relationship or identifying combination. The retention setting for improvement data is not a promise about every category of stored data.

Smart Updates uses separate workspace opt-in, customer topic consent, preference and suppression controls. Enabling quality analysis does not subscribe customers to outreach.

Read the Privacy Policy, Terms of Service, Data Processing Agreement and sub-processor information for the applicable terms and disclosures.

For deployment-specific security information, contact the team.