PepoChat

Security overview

How credentials, conversations and knowledge are protected, the account and data controls, and the guardrails around every outbound call.

PepoChat sits between your customers and your tools, so it is built to expose as little as possible in either direction. This page lists what is in place; it states facts about the product, not certifications.

Your workspace is isolated

Each workspace's knowledge base, conversations, contacts, credentials and settings are stored in separate namespaces. A visitor's session can read only its own conversations, and only inside the workspace it was created in. Team members sign in with a verified email and a password, or with Google.

Account security

Every team member can turn on two-factor authentication from their Profile page: a six-digit code from an authenticator app on each sign-in, with password or with Google, plus single-use backup codes and an optional 30-day trust for the devices they use every day. Sign-up, sign-in, password resets and the two-factor endpoints are limited per IP address, and sign-in can be protected by a bot check.

Credentials are encrypted and never shown again

Integration keys, OAuth secrets, refresh tokens, Notion and Google Drive grants and custom-action header values are encrypted with AES-256-GCM before they are stored. The dashboard shows header names, never values. Webhook URLs, which are the credential for Slack, Discord and Zapier, are stored as the action URL and are visible to workspace members; rotate them in the tool if they leak.

The agent reads only what you allow

Every action declares the response fields the agent may read. Everything else in a tool's reply, including personal data, never reaches the model. The agent summarises results and never repeats raw API output. Google Drive access is limited to the files you pick in Google's picker; Notion access to the pages you share on Notion's consent screen.

Outbound calls are guarded

Every call the agent makes to your tools is HTTPS-only, refuses private and internal hosts (checked by name and by DNS-over-HTTPS resolution), does not follow redirects, times out after 10 seconds, caps the response size, and escapes visitor input for the exact place it lands (URL, header, JSON, form or XML). Inputs with a known format are validated before any request.

Knowledge is treated as data, not instructions

Content retrieved from your knowledge base and results from tools are wrapped as untrusted data inside the prompt, so an instruction planted on a web page cannot steer the agent. Your own agent instructions and guardrails are wrapped the same way and placed after the base rules, so they can shape tone and add refusals but cannot switch off the rules that keep the agent honest. Only the visitor's own explicit request can trigger a booking or an action.

Identity and personal context

Chats start anonymous. Personal features, meeting memory and pre-filled bookings, unlock only after a visitor verifies an email with a six-digit code that expires in 10 minutes, allows 5 attempts and is stored only as a hash. A transcript is emailed only to such a verified address, only for a resolved conversation, and only on the visitor's request. See Visitor email verification.

Abuse protection

Public endpoints are rate limited per visitor session and per workspace: message sending, new conversations, verification emails, transcript emails, lead-capture submissions, votes and session creation each have their own limits. Messages are capped at 4,000 characters. Test sessions for the Test the agent drawer are created only for signed-in team members, so nobody can obtain free replies by adding a parameter to the widget URL. Dashboard actions such as assignment, notes, exports and knowledge changes are limited per workspace as well.

Where the widget may run

The allowed-domains list restricts which sites can start a conversation with your agent. It is checked when a visitor's session is created and blocks casual misuse of your Organization ID. The hosted chat page is blocked by an allowlist until you switch on Allow the hosted chat page. Blocked countries refuse sessions from the countries you list, based on the visitor's IP address, and fail open when the country is unknown. See Allowed domains.

Data controls

  • Data retention on the Team page deletes resolved conversations, transcript included, after 30 to 365 days; off by default, owners and admins only. See Team members and roles.
  • Export CSV in the inbox and on the Contacts page gives you a copy of conversations and contacts; the inbox export link expires after one hour.
  • Internal notes never leave the dashboard: they are not sent to the widget, not read by the agent and not included in exports.
  • Test chats never count toward billing, analytics or Contacts.

Services involved

The backend runs on Convex, the dashboard and website on Vercel, AI replies use OpenAI models, transactional email goes through Resend, voice through Vapi when you enable it, and billing through Dodo Payments. PepoChat never stores your card details.

Reporting a vulnerability

Email support@pepochat.com with "Security" in the subject line. Please do not publish details until we have replied.

Something missing or wrong on this page? Tell us and we will fix it.