Security at Way2Chat
What we do to protect your account and your customers' conversations β described plainly, without badges we haven't earned.
Your data is separated from everyone else's
Account isolation
Every request is checked against the account that owns the data. We run automated tests that try to reach one account's conversations from another and confirm they are refused.
Least-privilege access
Agents can only read a conversation once they claim it, agents limited to one website stay on it, and assistant logins can view but never send.
Payments stay with the processor
Card details go straight to our payment provider, a PCI DSSβcompliant processor. Card numbers never touch our servers.
Protecting accounts
- Passwords and API keys are stored only as bcrypt hashes; we cannot see them.
- Sign-in, sign-up, password reset and verification-code requests are rate limited to slow down guessing and abuse.
- Session cookies are
HttpOnly,SecureandSameSite, and sessions reject identifiers they did not issue. - Forms that change data are protected against cross-site request forgery.
- Changing an account's sign-in email requires the current password and confirmation from the new address, and both addresses are told.
Protecting data in transit
- All traffic uses HTTPS, and browsers are told to use HTTPS only (HTTP Strict Transport Security).
- Pages cannot be framed by other sites, browsers are told not to guess content types, and camera, microphone, location and payment APIs are disabled.
- Payment webhooks are verified with a cryptographic signature before we act on them.
Infrastructure
The service runs on managed infrastructure provided by Hostinger in the United States. Scheduled jobs remove expired sessions, one-time tokens and old rate-limit records automatically. Our Sub-processors page lists every provider that handles personal data.
Certifications
We are not currently certified to SOC 2 or ISO 27001. If you need a completed security questionnaire for your own compliance process, email admin@way2chat.com.
Reporting a vulnerability
If you believe you have found a security issue, please email admin@way2chat.com with the steps to reproduce it and its likely impact. We aim to acknowledge reports within three business days and will keep you updated while we fix it.
We will not take legal action against research carried out in good faith that follows these rules:
- Only test against an account you own, and never access, change or delete another customer's data.
- Do not run denial-of-service attacks, spam, social engineering or physical attacks.
- Give us reasonable time to fix the issue before telling anyone else about it.
Our machine-readable contact details are published at /.well-known/security.txt.