Skip to content
Trust

Security

No online system can promise it will never be breached. What we can do is limit the chance and the impact of a problem, and be open about how.

Workspace isolation

Every business has its own workspace. Access is checked in the application and enforced again by PostgreSQL row-level security, so one missed check in code does not expose another business.

Accounts

Two-factor authentication is required for owners and admins and available to everyone. Recovery codes are stored as one-way hashes and work once. You can see and end your active sessions.

Sensitive actions

Changing roles, managing two-factor settings and closing a workspace require you to confirm your identity again.

Audit trail

Changes to members, roles and settings are written to an append-only log that the application cannot edit or delete.

AI boundaries

AI drafts replies from your published knowledge and current catalog only. It cannot issue refunds, give discounts, change roles or mark payments as paid.

What we do not claim

makchat does not currently hold a security certification. An independent penetration test is required before our production launch, and we will publish a summary when it is complete.

Found a vulnerability? Email security@makchat.example with details. Please do not test against other customers' data.