← Back to home

Security

Last updated: 21 September 2026

Your customers trust you with their questions, and you trust us with those conversations. This page explains how we protect them and how to report a vulnerability.

Hosting and encryption

  • Database, file storage and application servers run in the EU (Frankfurt, Germany).
  • All traffic is encrypted with TLS; HSTS is enforced. Data is encrypted at rest.
  • Access tokens for connected Gmail/Outlook inboxes are additionally encrypted with AES-256-GCM, and we revoke them when an inbox is disconnected.

Access control

  • Every workspace is isolated at the database level with row-level security; roles (admin/agent) are enforced server-side.
  • Passwordless sign-in (magic link or Google) and optional two-factor authentication with an authenticator app, enforced in the database once enabled.
  • Attachments are private and only available through short-lived signed links to members of the workspace.

Application security

  • Inbound email is sanitised; scripts never run; remote images are blocked until an agent chooses to load them; executable attachments are blocked.
  • Public endpoints (the chat widget) are rate-limited and every visitor can only access their own conversation.
  • Security headers (HSTS, frame protection, content-type sniffing protection), automated dependency updates and regular security reviews.

Privacy by design

Responsible disclosure

Found a vulnerability? Please email hello@suppp.chat with the details. We'll confirm receipt within 3 working days and keep you updated.

  • Give us reasonable time to fix the issue before sharing it with others.
  • Don't access, change or delete data that isn't yours — use your own test account and workspace.
  • No denial-of-service, social engineering, spam or physical attacks.

If you follow these rules, we won't take legal action against you and we're happy to credit you for your finding.