Security by design

Customer support data deserves careful handling.

HelpoSoft includes practical application safeguards and gives operators a clear foundation for their own hosting, privacy and compliance program.

🔐

Credentials protected

Passwords use PHP’s adaptive password hashing. API tokens are stored as one-way SHA-256 hashes, while AI and webhook secrets are encrypted with the application key.

🧱

Tenant isolation

Dashboard and API queries are scoped by workspace so customers only access their own sites, contacts, tickets and conversations.

🛡️

Request safeguards

CSRF tokens protect dashboard writes, prepared statements protect database queries, and rate limits cover public widget and API requests.

🧾

Audit trail

Important agent actions can be recorded with workspace, user, IP address, subject and context for operational review.

Deployment responsibility

Before handling production customer data, configure HTTPS, backups, SMTP, retention rules, privacy terms, server monitoring and jurisdiction-specific compliance. Commission a professional security review before high-risk or regulated use.