SECURITY AT SPEAKTO

Customer trust is an operating requirement.

Speakto is designed around tenant isolation, role-aware access, protected credentials, auditable activity, and controlled AI knowledge retrieval.

Tenant isolation

Application data is scoped to the authenticated workspace. Website, assistant, knowledge, contact, ticket, channel, billing, and staff resources are separated by tenant.

Role-based access

Workspace roles and custom permissions restrict access to operational modules and administrative actions.

Protected credentials

Provider, channel, webhook, and SMTP secrets use encrypted storage and write-only API fields; saved secrets are not returned to the browser.

Session and API control

Short-lived access tokens, refresh rotation, scoped API keys, one-time secret presentation, and rate limits reduce credential exposure.

AI and knowledge controls

Assistants can be assigned to specific knowledge bases and websites. Retrieval configuration, source status, response policy, confidence controls, and human handoff reduce the risk of an assistant answering beyond approved material.

Infrastructure and operations

Production deployments should use TLS, secure environment secret management, restricted database and object-storage access, monitored backups, dependency updates, and logging appropriate to the customer’s deployment model.

Report a security concern

Send a concise report to security@speakto.ai with the affected surface, reproduction steps, impact, and a safe contact method. Do not include live secrets or unrelated customer data. We will acknowledge and triage credible reports.