Skip to content

Security & privacy

Claims we can stand behind

This page reflects the product security model. We do not claim SOC 2 or other certifications we have not completed. We do not name a hosting region or provider as a current fact.

  • Tenant isolation by store_id

    Session tokens carry a verified store_id. Queries and chat history are scoped to that tenant — never taken from browser-supplied store identifiers alone.

  • No secrets in the widget

    The storefront only uses a public store key to start a session. Session tokens are issued after origin validation. OpenAI keys never ship in the browser.

  • Encrypted Magento credentials

    OAuth / integration credentials are stored encrypted at rest. Secrets and OpenAI keys are never hardcoded or logged.

  • Retention intent

    Visitor IPs are stored as hashes. Conversations support retention windows (default target: 90 days) and deletion endpoints. Model calls receive question text — not unnecessary personal profiles.

  • No SOC 2 in v1

    We do not claim SOC 2 or ISO certification. We publish isolation, encryption, and retention — not a certificate wall.

  • Abuse controls

    Multi-layer rate limiting (IP, session, store) and CORS allow-lists for registered storefront origins.

How isolation applies to Magento chat: AI chatbot for Magento 2 and Hyvä. Legal details: Privacy Policy, Cookie Policy, and Terms.

Next step

Questions about isolation or retention?

Request integration and we will review your Magento / Hyvä store. We invoice after fit — no payment on the form.

Request integration
Security · Claspwell