Data security.
How Message protects access to customer conversations, connected accounts and company knowledge.
01Workspace access
Account permissions and workspace checks govern access to conversations, settings and customer information. Use individual team accounts and assign the permissions needed for each person’s work.
02Connected credentials
Integration access and refresh tokens use application-level AES-256-GCM encryption before database storage. Provider authorization and connector scope determine which operations an integration can perform. Remove connections that your workspace no longer needs.
03Customer identity
A CRM record found using an email address is agent context, not proof of the visitor’s identity. Private order information requires the supported customer-verification flow. Public knowledge and private customer context have separate access rules.
04AI and company knowledge
Message AI uses company knowledge and approved connected sources. Company guidance belongs to its workspace. Review generated knowledge before publication and grant access only to the sources intended for customer support.
05Security review
Request current information about hosting, backups, access controls, testing and incident procedures from [email protected]. Requirements such as a specific retention window, regional restriction or contractual assurance need written confirmation for your deployment.
06Attestations
This page does not assert that Message holds a SOC 2 report, ISO 27001 certificate or HIPAA certification. Obtain current evidence and any required agreement before relying on a compliance requirement.
07Report a concern
Send a concise description, affected URL and safe reproduction steps to [email protected]. Do not include passwords, access tokens or other customers’ records. Do not access, alter or remove data while investigating a concern.