Security

Your customers’ details are in our care. Here’s how we protect them.

Tenant isolation
Every database query, vector search and realtime channel is scoped by business ID. Unscoped queries can’t be written.
Encryption
Contact fields are encrypted with AES-GCM, bound to the conversation ID as additional data. The keyring supports rotation.
Authentication
PBKDF2 password hashes, HttpOnly + SameSite session cookies, a CSRF header plus Origin check, and re-auth for sensitive actions.
Widget security
Short-lived signed tokens, a domain allowlist, an isolated iframe and a strict CSP. The loader never reads your page’s DOM.
Crawler
SSRF-hardened: private IP ranges are blocked, robots.txt is respected, redirects are capped.
AI safety
Prices come only from the deterministic engine; a money guard blocks numbers your rules didn’t produce, mid-stream. A circuit breaker falls back to a reliable mode when a provider fails.
Audit
Publishing, rollbacks, role changes and exports are written to an audit log.

Found a vulnerability?security@yixnova.com