Security

Customer context.
Considered access.

Your support workspace connects conversations, knowledge and business systems. Set the boundaries for each of them, and give your team the access their work requires.

Keep useful knowledge.
Control what connects.

Message AI works with workspace knowledge and supported connected sources. Review the content and the permissions before making it part of customer support.

01

Workspace permissions

Use workspace roles and department permissions to decide who can administer settings and work on customer conversations. Give each teammate their own account so assignments and actions stay attributable.

02

Connected accounts

Connect through the supported provider flow and review the requested permissions. Select the sources your workspace needs. Disconnect accounts you no longer use, and revoke provider access when appropriate.

03

AI knowledge boundaries

Public help content and private customer records serve different purposes. Approve content for AI knowledge, and use supported identity-verification flows before returning customer-specific order information.

04

Controlled integrations

Keep credentials on the server. For your own endpoint, expose only the fields and read-only operations needed for the support workflow. Do not put administrative credentials in the chat widget.

05

Account and activity review

Review workspace membership, role changes and the audit information available in your account. Remove departing teammates and rotate credentials held by systems you retire.

06

Human review where it matters

Knowledge drafts need review. Customer identity needs verification. Sensitive decisions need a person with the authority to make them. An AI-generated answer is not a substitute for those controls.

Security review

Ask for the details
your business needs.

Need a security questionnaire, information about data handling or a specific contractual requirement? Send the requirement to our team for review before connecting sensitive data.

Do not assume SOC 2, ISO 27001 certification or a HIPAA agreement from a product feature. Request the applicable evidence or signed agreement.

Start a security review

Found a security issue?

Email [email protected] with the affected page, steps to reproduce and a minimal example. Avoid accessing other customers’ data. Please send credentials or sensitive evidence only through a channel arranged with our team.

Read policies and reporting options