Skip to main content

Preparing for public launch. Book a personalized walkthrough

Built for trust from day one

Security and privacy aren't add-ons. Every Supportweave workspace ships with the controls security reviewers typically ask for, and the guardrails that keep AI actions safe.

Security baked into every workspace

Not an enterprise add-on — every Supportweave workspace ships with these controls from day one.

Audit trail

Every security and account event is logged: who did what, when, with CSV export.

GDPR export & erasure

Per-workspace data export and right-to-be-forgotten delete, built in.

Data retention

Set a per-workspace window; a daily job auto-purges old conversations and messages.

Secrets encrypted at rest

Channel credentials are AES-GCM encrypted at rest and are not exposed to the model or to client-side code.

Enforced 2FA

TOTP two-factor enrollment and an enforced login challenge.

Outbound safety (allow-list)

Outbound agent actions are restricted to destinations you've explicitly allow-listed, with server-side protections on every outbound request.

Tenant isolation

Strict per-workspace tenant isolation across the platform.

Signed webhooks

Inbound provider webhooks are signature-verified; outbound webhooks are HMAC-signed.

Data ownership

Your data stays yours

We don't train foundation models on your content. Channel credentials are encrypted at rest and never exposed to the model. Export or delete your data anytime.

  • Regional deployment available by written agreement
  • Per-workspace retention windows with auto-purge
  • DPA and subprocessor list available on request

Security questions? We're an open book.

Get the trust details your team needs to say yes.