This document is also available in Turkish. If the two versions differ, the Turkish version prevails.
1. Infrastructure
- servers run in security-certified data centers, which provide physical security
- all traffic passes through an attack-protected network; servers are reachable only on the ports they need
- server administration uses key-based authentication only; password login is disabled
- the operating system and dependencies are updated regularly
2. Encryption
- all connections between browsers, mobile apps, the chat widget and our servers are encrypted with TLS
- passwords are stored as one-way argon2id hashes; plain-text passwords are never kept
- two-factor secrets and integration secrets are stored encrypted in the database
- in the mobile app, the session key is stored in the phone’s secure storage; signing out deletes it along with the notification token
- push notifications are sent only while the agent isn’t active in the console or the app; message previews can be turned off by the agent
- backups are encrypted with AES-256
3. Account and access security
- two-factor authentication with an authenticator app; the workspace owner can require it for the whole team
- separation of permissions through owner, admin, supervisor and agent roles
- an option to restrict console access to specific IP addresses
- session length and inactivity sign-out settings
- an email alert when someone signs in from a new device, and a notice when the password or two-factor settings change
- temporary blocking and rate limiting after failed sign-in attempts
- session cookies are HttpOnly, Secure and SameSite=Strict, with protection against cross-site request forgery
4. Application security
- each workspace’s data is separated from the others at application and database level; every query is scoped to the workspace ID
- visitor and agent content is sanitized before display; help center articles are rendered with a safe formatting subset
- uploaded files are virus-scanned and limited to allowed types
- inbound email notifications are verified by signature; requests that fail verification are rejected
- no release goes live without passing automated security tests
- AI features run on our own servers; conversations are not sent to external services
5. Logging and monitoring
- significant console actions (setting changes, adding and removing agents, deleting and exporting data) are written to a tamper-proof activity log that admins can view
- system resources and service health are monitored continuously, and our team is alerted immediately to anything unusual
6. Backups and continuity
- the database and files are backed up daily with encryption; backups can also be kept in a separate location
- backups are kept for up to 30 days, and restores are tested regularly
7. Privacy tools
- a retention period for chats, with expired chats deleted automatically
- masking of visitor IP addresses after a set period
- finding, exporting and deleting all of a visitor’s data (including chats, emails and tickets)
- turning file uploads off and limiting allowed file types
8. Personnel and incident response
- access to Customer Data is limited to the staff who need it and is under a confidentiality obligation
- in a security incident we contain it, investigate its impact and notify affected customers within 48 hours at the latest
9. Reporting a vulnerability
If you think you’ve found a security vulnerability in Layvchat, send the details to [email protected]. We review reports as soon as possible and tell you the outcome.
We will not take legal action over good-faith research that follows these rules:
- use only your own account and data; do not access, change or delete other customers’ data
- do not run tests that slow down or interrupt the Service (load testing, denial of service)
- do not disclose the issue publicly before we have had reasonable time to fix it
