Security & Trust

Security & Data Protection

AIChatVault is built so that business knowledge, customer conversations and connected integrations stay within controls your organization defines — encrypted where it matters, isolated per organization, and scoped to only the access each connection actually needs.

Encrypted Credentials

Integration credentials and connected-account tokens are stored encrypted at rest.

Organization Isolation

Conversations, leads and integration data are scoped to your organization by design.

Scoped OAuth Access

Third-party connections use OAuth 2.0 with organization-scoped, revocable tokens.

Rate-Limited APIs

API and webhook endpoints are throttled to protect against abusive request volume.

01

Encryption & Credential Handling

Passwords are never stored in plain text — AIChatVault hashes account passwords using bcrypt. Sensitive integration data, including connected-account credentials and channel access tokens, is stored using encrypted fields rather than plain database columns, so the raw values aren't exposed even if the underlying record is viewed directly.

  • Account passwords are hashed, never stored or logged in plain text.
  • Connected-channel and store-integration credentials use encrypted storage.
  • Lead and customer records captured through the platform are similarly protected.

What This Covers

Account Authenticationbcrypt password hashing on every account.
Integration CredentialsWhatsApp, Instagram, Messenger and connected-store access tokens stored encrypted.
Customer RecordsLeads captured through your agent are stored with the same protection.

How Isolation Works

Every record is organization-scopedConversations, integrations and delivery logs carry an organization identifier that every query is filtered by.
No cross-organization accessApplication logic authorizes every request against the requesting user's own organization.
02

Organization-Level Data Isolation

AIChatVault is a multi-tenant platform, and every piece of customer data — conversations, leads, knowledge sources, integration connections and delivery history — belongs to a specific organization. Access is authorized against that organization on every request, so one customer's data is never visible to another.

03

Access Controls

Workspace access is managed per organization. Accounts are assigned roles and permissions rather than every team member sharing one login, and the number of workspace seats available is determined by your plan. The account owner controls who has access to agents, conversations and configuration.

  • Role-based permissions control what each team member can view and change.
  • Workspace seats are managed per organization, scaling with your plan.
  • Account passwords are hashed with bcrypt on every login attempt.
04

Integration & OAuth Security

Connections to third-party platforms — including Zapier's account-based connection — use OAuth 2.0 rather than shared static credentials. Each authorization is scoped to a single organization, tokens can be revoked at any time from inside your workspace, and disconnecting a provider immediately revokes its active access.

  • OAuth 2.0 authorization for supported connected accounts.
  • Tokens are issued per organization and can be revoked on demand.
  • Disconnecting an integration immediately revokes its stored access.
05

Webhook & API Protection

Outbound webhook destinations are validated before AIChatVault will send data to them, blocking requests aimed at private, internal or otherwise unsafe network addresses rather than trusting whatever URL is configured. API and webhook endpoints are also rate-limited to protect against abusive or runaway request volume.

06

Human Oversight & Controlled AI Actions

AI agents operate within the knowledge, instructions and escalation rules your organization configures. Businesses decide which actions an agent is permitted to take through connected integrations, and can configure human handoff for conversations that need a person's judgement rather than letting every interaction resolve automatically.

07

Your Data, Your Control

You control the knowledge sources your AI agents use and can update or remove them at any time. Integrations you connect can be disconnected from your workspace whenever you choose, immediately revoking their access. For account data or deletion requests, contact our support team directly.

08

AI Provider Processing

Conversations are processed using the AI models configured for your plan, provided by established AI model providers. AIChatVault does not use your business knowledge or customer conversations to train third-party foundation models.

AIChatVault does not currently publish formal third-party compliance certifications such as SOC 2, HIPAA or ISO 27001. If your organization requires a specific compliance certification, security review or data processing agreement, contact our team to discuss your requirements.

Have a Security Question?

Whether you're evaluating AIChatVault for your business or reporting a potential security issue, our team will route it to the right person.