Credentials protected
Passwords use PHP’s adaptive password hashing. API tokens are stored as one-way SHA-256 hashes, while AI and webhook secrets are encrypted with the application key.
HelpoSoft includes practical application safeguards and gives operators a clear foundation for their own hosting, privacy and compliance program.
Passwords use PHP’s adaptive password hashing. API tokens are stored as one-way SHA-256 hashes, while AI and webhook secrets are encrypted with the application key.
Dashboard and API queries are scoped by workspace so customers only access their own sites, contacts, tickets and conversations.
CSRF tokens protect dashboard writes, prepared statements protect database queries, and rate limits cover public widget and API requests.
Important agent actions can be recorded with workspace, user, IP address, subject and context for operational review.
Before handling production customer data, configure HTTPS, backups, SMTP, retention rules, privacy terms, server monitoring and jurisdiction-specific compliance. Commission a professional security review before high-risk or regulated use.