← Back to home
Security
Last updated: 21 September 2026
Your customers trust you with their questions, and you trust us with those conversations. This page explains how we protect them and how to report a vulnerability.
Hosting and encryption
- Database, file storage and application servers run in the EU (Frankfurt, Germany).
- All traffic is encrypted with TLS; HSTS is enforced. Data is encrypted at rest.
- Access tokens for connected Gmail/Outlook inboxes are additionally encrypted with AES-256-GCM, and we revoke them when an inbox is disconnected.
Access control
- Every workspace is isolated at the database level with row-level security; roles (admin/agent) are enforced server-side.
- Passwordless sign-in (magic link or Google) and optional two-factor authentication with an authenticator app, enforced in the database once enabled.
- Attachments are private and only available through short-lived signed links to members of the workspace.
Application security
- Inbound email is sanitised; scripts never run; remote images are blocked until an agent chooses to load them; executable attachments are blocked.
- Public endpoints (the chat widget) are rate-limited and every visitor can only access their own conversation.
- Security headers (HSTS, frame protection, content-type sniffing protection), automated dependency updates and regular security reviews.
Privacy by design
- AI features are off by default and opt-in per workspace.
- Workspace admins can set automatic data retention, export or erase all data about a contact, and delete their workspace entirely.
- See our privacy policy, data processing agreement and subprocessors.
Responsible disclosure
Found a vulnerability? Please email hello@suppp.chat with the details. We'll confirm receipt within 3 working days and keep you updated.
- Give us reasonable time to fix the issue before sharing it with others.
- Don't access, change or delete data that isn't yours — use your own test account and workspace.
- No denial-of-service, social engineering, spam or physical attacks.
If you follow these rules, we won't take legal action against you and we're happy to credit you for your finding.