Tenant isolation
Application data is scoped to the authenticated workspace. Website, assistant, knowledge, contact, ticket, channel, billing, and staff resources are separated by tenant.
Speakto is designed around tenant isolation, role-aware access, protected credentials, auditable activity, and controlled AI knowledge retrieval.
Application data is scoped to the authenticated workspace. Website, assistant, knowledge, contact, ticket, channel, billing, and staff resources are separated by tenant.
Workspace roles and custom permissions restrict access to operational modules and administrative actions.
Provider, channel, webhook, and SMTP secrets use encrypted storage and write-only API fields; saved secrets are not returned to the browser.
Short-lived access tokens, refresh rotation, scoped API keys, one-time secret presentation, and rate limits reduce credential exposure.
Assistants can be assigned to specific knowledge bases and websites. Retrieval configuration, source status, response policy, confidence controls, and human handoff reduce the risk of an assistant answering beyond approved material.
Production deployments should use TLS, secure environment secret management, restricted database and object-storage access, monitored backups, dependency updates, and logging appropriate to the customer’s deployment model.
Send a concise report to security@speakto.ai with the affected surface, reproduction steps, impact, and a safe contact method. Do not include live secrets or unrelated customer data. We will acknowledge and triage credible reports.