Skip to content

Last updated: October 7, 2026

Security

The technical and organizational measures we take to protect your data, the security tools we give you, and how to report a vulnerability.

This document is also available in Turkish. If the two versions differ, the Turkish version prevails.

1. Infrastructure

  • servers run in security-certified data centers, which provide physical security
  • all traffic passes through an attack-protected network; servers are reachable only on the ports they need
  • server administration uses key-based authentication only; password login is disabled
  • the operating system and dependencies are updated regularly

2. Encryption

  • all connections between browsers, mobile apps, the chat widget and our servers are encrypted with TLS
  • passwords are stored as one-way argon2id hashes; plain-text passwords are never kept
  • two-factor secrets and integration secrets are stored encrypted in the database
  • in the mobile app, the session key is stored in the phone’s secure storage; signing out deletes it along with the notification token
  • push notifications are sent only while the agent isn’t active in the console or the app; message previews can be turned off by the agent
  • backups are encrypted with AES-256

3. Account and access security

  • two-factor authentication with an authenticator app; the workspace owner can require it for the whole team
  • separation of permissions through owner, admin, supervisor and agent roles
  • an option to restrict console access to specific IP addresses
  • session length and inactivity sign-out settings
  • an email alert when someone signs in from a new device, and a notice when the password or two-factor settings change
  • temporary blocking and rate limiting after failed sign-in attempts
  • session cookies are HttpOnly, Secure and SameSite=Strict, with protection against cross-site request forgery

4. Application security

  • each workspace’s data is separated from the others at application and database level; every query is scoped to the workspace ID
  • visitor and agent content is sanitized before display; help center articles are rendered with a safe formatting subset
  • uploaded files are virus-scanned and limited to allowed types
  • inbound email notifications are verified by signature; requests that fail verification are rejected
  • no release goes live without passing automated security tests
  • AI features run on our own servers; conversations are not sent to external services

5. Logging and monitoring

  • significant console actions (setting changes, adding and removing agents, deleting and exporting data) are written to a tamper-proof activity log that admins can view
  • system resources and service health are monitored continuously, and our team is alerted immediately to anything unusual

6. Backups and continuity

  • the database and files are backed up daily with encryption; backups can also be kept in a separate location
  • backups are kept for up to 30 days, and restores are tested regularly

7. Privacy tools

  • a retention period for chats, with expired chats deleted automatically
  • masking of visitor IP addresses after a set period
  • finding, exporting and deleting all of a visitor’s data (including chats, emails and tickets)
  • turning file uploads off and limiting allowed file types

8. Personnel and incident response

  • access to Customer Data is limited to the staff who need it and is under a confidentiality obligation
  • in a security incident we contain it, investigate its impact and notify affected customers within 48 hours at the latest

9. Reporting a vulnerability

If you think you’ve found a security vulnerability in Layvchat, send the details to [email protected]. We review reports as soon as possible and tell you the outcome.

We will not take legal action over good-faith research that follows these rules:

  • use only your own account and data; do not access, change or delete other customers’ data
  • do not run tests that slow down or interrupt the Service (load testing, denial of service)
  • do not disclose the issue publicly before we have had reasonable time to fix it