Security Overview
How Concierge protects accounts, visitor information, provider connections, and service operation.
Last updated: August 19, 2026
Security design
- Authentication, session controls, platform roles, site permissions, and protected administrative routes.
- Encrypted network transport and server-side secret handling.
- Encrypted storage for supported provider OAuth credentials and restricted credential access.
- Input validation, public-write rate limits, security headers, request identifiers, and operational logging.
- Stripe webhook signature verification and provider-specific connection validation.
- Tenant-aware service authorization and administrative audit evidence for sensitive workflows.
Data and provider security
We limit providers and personnel to access reasonably needed for service operation. Customers control connected sites, teammates, provider accounts, routing destinations, and source content. Our Subprocessors page identifies major service categories and providers.
Security validation
Concierge uses code review, automated type and policy checks, dependency and secret scanning, security smoke tests, permission tests, backup validation procedures, and operational probes. Some assurance work remains ongoing, including broader cross-tenant integration coverage, distributed rate-limit validation, billing replay drills, prompt-injection evaluation, enforced content security policy, and independent penetration testing.
Incident handling
We investigate suspected unauthorized access, data exposure, credential compromise, abuse, and provider incidents; contain the affected system; preserve appropriate evidence; remediate the cause; and notify affected parties or authorities when legally required.
Customer responsibilities
- Use unique credentials and protect account access.
- Grant the minimum teammate and provider permissions needed.
- Review routing destinations, public Pages, connected domains, and source content.
- Remove former teammates and revoke unused connections promptly.
- Do not place secrets, passwords, payment credentials, or unnecessary sensitive information in Agent sources or conversations.
Report a vulnerability
Follow Security Reporting or email support@poweredbyconcierge.com. Do not include exploit code or sensitive data in the initial email.