Security
How we protect your information
A plain description of the measures in place. If you spot something that looks wrong, please tell us — we'd rather hear it early.
Last updated 7 September 2026
Separated by design
Every chat, message and uploaded file is stored against the account that created it, and the database refuses to return one person's records to anyone else — that rule is enforced at the data layer, not just hidden in the app.
Files
Uploads go to private storage in a folder tied to your account. Links are short-lived and generated on demand, so a copied link stops working. We limit file types and sizes.
In transit and at rest
Everything travels over encrypted connections (HTTPS), and the database and file storage are encrypted at rest by our hosting provider. Backups are taken regularly and are encrypted too.
Who on our side can see your data
Access to customer records is limited to team members who need it, granted through a separate permissions list that only an administrator can change. Every time a staff member opens or edits a customer record it is written to an access log.
Keys and secrets
Credentials for the AI, email and database services live only on our servers. They are never sent to your browser and never stored in our source code.
If something goes wrong
We have a written process for handling a suspected breach: contain, assess, notify the relevant regulator within 72 hours where required, and tell affected people what happened and what to do. Report a security concern to [security@yourdomain.com]; we'll acknowledge within two working days and won't pursue anyone who reports a genuine issue in good faith.
What we ask of you
Use a strong, unique password, turn on two-factor authentication where offered, and avoid pasting passwords, card numbers or other people's sensitive details into the chat.
This is a plain-English draft written for clarity, not a substitute for legal advice. Have a qualified adviser review it — and replace the placeholder company details — before you rely on it.