Chattypie
  • Fiyatlandırma
Giriş yapÜcretsiz Başlayın→

Security

Last updated: April 19, 2026

1. Overview

Chattypie is built by a small team for teams that care about their customers' data. This page describes, in plain language, how we protect the information you and your customers send through our platform, and where we are honest about the work that is still ahead of us.

If you have a security question that this page does not answer, email [email protected].

2. Encryption in Transit

Every connection between your browser, your customers' browsers, our servers, our database, and our object storage provider is encrypted with TLS (HTTPS). Our web endpoints use certificates issued by Let's Encrypt and renewed automatically. Database connections require TLS ("sslmode=require"). There is no plaintext path into the system.

3. Encryption at Rest

All stored data is encrypted at rest using AES-256, delegated to our underlying providers:

  • Database (Neon): customer accounts, conversations, messages, contacts, and settings. Neon encrypts all stored data and backups by default.
  • File attachments (Cloudflare R2): images, documents, and media uploaded through the chat widget or agent inbox. R2 encrypts all objects at rest by default.
  • Authentication secrets: passwords and sessions are managed by Clerk. We do not store or see your password.

Encryption keys are managed by these providers. We do not currently offer customer-managed keys (CMEK / BYOK); see "What we are not yet doing" below.

4. Infrastructure

Data flows through a small, deliberate set of providers:

  • Application servers: Hetzner (European Union data centers). These servers are stateless. No customer data is persisted to their local disks.
  • Database: Neon (serverless PostgreSQL), AWS-backed. This is where all persistent customer records live.
  • Object storage: Cloudflare R2 for uploaded files.
  • Identity: Clerk for user authentication and session management.
  • Payments: Stripe for subscription billing. We never see or store full card numbers.

5. Authentication and Access Controls

User authentication is handled by Clerk, with support for email + password, Google OAuth, and more methods over time. JWT sessions are validated on every API request.

Inside a workspace, permissions are enforced by a role-based access control (RBAC) system with three default roles (Admin, Agent, and Viewer) and per-resource permissions that admins can tune. API access for integrations uses workspace-scoped API keys.

All public API routes pass through per-category rate limits (authentication attempts, public widget messages, AI operations, uploads, etc.) to slow down abuse and protect the system from accidental misuse.

6. Third-Party Processors

We share specific data with the providers listed in Section 4 strictly to operate the Service. The full list (including what we send to each and links to their own security and privacy pages) will be published at our Subprocessors page once it is live. In the meantime, the relevant providers are referenced in our Privacy Policy.

We also use PostHog (hosted in the European Union) for product analytics and session replay inside our authenticated dashboard. We take reasonable steps to limit the collection of sensitive content (including customer conversations, contact details, form inputs, and attachments) in these recordings. See PostHog's privacy policy for details on their data handling.

7. AI and Conversation Content

When AI features are enabled in your workspace, conversation content is sent to our AI provider (currently OpenAI) so the model can generate replies, summaries, or suggestions. This is disclosed in detail in our Privacy Policy. We do not currently perform automated redaction of personal information before sending conversation content to AI providers. If you do not want conversation content sent to AI providers, do not enable AI features in your workspace.

8. Responsible Disclosure

If you believe you have found a security vulnerability, please email [email protected] with "SECURITY" in the subject. We acknowledge reports within 72 hours and keep reporters updated until resolution. We do not currently run a paid bug bounty program.

Please give us a reasonable window to investigate and fix an issue before disclosing it publicly.

9. What We Are Not Yet Doing

We think it is more useful to tell you what we have not built yet than to overstate what we have. Today, Chattypie does not have:

  • A SOC 2 Type II report or ISO 27001 certification
  • A formal third-party penetration test on file (automated dependency scanning and pre-commit secret scanning are in place)
  • Customer-managed encryption keys (CMEK / BYOK). Encryption is handled by our providers with their keys
  • Automated redaction of personal information from conversation content before it is sent to AI providers (we do offer a per-user opt-out; see Profile → Privacy)
  • A published subprocessor list or Data Processing Agreement (DPA) page (coming soon)
  • 24/7 on-call rotation. Incident response is single-operator and best-effort outside business hours

These gaps are tracked publicly on GitHub. If any of them is a dealbreaker for your team, tell us. Knowing which gap matters most helps us prioritize.

10. Changes

We will update this page when material changes happen. The "Last updated" date at the top reflects the most recent change.

Chattypie

Yapay zeka destekli müşteri destek platformu.

Her şirket için tasarlandı.

Gelişmelerden haberdar olun

X

Ürün

Demo talep edin

Özellikler

Canlı SohbetYapay Zeka TemsilcisiOrtak Gelen KutusuBilgi BankasıOtomasyonlarAnalitik

Çözümler

SaaS içinE-ticaret içinGirişimler için

Kaynaklar

BlogYardım MerkeziBize UlaşınYapay Zeka Asistanları İçinGüvenlikKullanım KoşullarıGizlilik Politikasıİade PolitikasıAlt İşleyicilerDPA
Durum kontrol ediliyor…
Status page
© 2026 Chattypie. Tüm hakları saklıdır.|KoşullarGizlilik