Security & trust

    Clear controls for protecting your assistant workspace

    Security is a shared responsibility. VSCRM AI provides account, permission, credential, and website controls while your team decides who can access the workspace and what business content should be used.

    Platform safeguards

    The controls below reflect capabilities currently present in the platform.

    Encrypted transport

    The public application and API are served over HTTPS so supported clients transmit information through an encrypted connection.

    Authenticated workspaces

    Dashboard, company, billing, knowledge, conversation, and administration areas require authenticated access.

    Roles and module permissions

    Company administrators can assign admin, member, or viewer roles and control access to team, bot, conversation, analytics, knowledge, and billing modules.

    Managed API credentials

    External AI keys can be created, scoped, updated, and revoked from the workspace. Generated secrets should be stored only in protected server environments.

    Website-origin controls

    A chatbot can be restricted to its configured website so public widget requests are checked against the intended origin.

    Device notification registration

    Firebase Cloud Messaging tokens are registered to authenticated users and may be refreshed across supported browser and Android devices.

    Customer content and conversations

    Choose approved website pages, files, FAQs, and documents for assistant knowledge.
    Avoid uploading secrets, unnecessary personal data, or content your team is not authorized to use.
    Review insufficient-context answers and conversation access regularly.
    Replace outdated knowledge sources when policies, pricing, or product information changes.

    Your team’s security checklist

    Use strong, unique account credentials.
    Grant only the module access each teammate needs.
    Keep API keys in server-side secret storage.
    Revoke keys and team access that are no longer required.
    Keep website-domain settings and notification devices current.

    Report a security or privacy concern

    Do not include passwords, API secrets, or sensitive customer content in the first message. Share a clear description and our support team will coordinate the next step.

    Contact support