Trust
Security
How AnswerTide protects your workspace and your customers' conversations. Last updated 4 October 2026. The overview is on Trust and security.
Items marked “Rolling out” are built and tested, and are being switched on as our database update rolls out.
Encryption
- In transit: the site, the dashboard, the assistant and our API are served only over HTTPS. Plain HTTP requests are redirected to HTTPS.
- Sign-in sessions: session cookies can't be read by page scripts, are sent only over HTTPS, and are not sent on requests that other sites start in the background.
- Keys you give us for actions: encrypted in our database with a separate key that is not stored in the database.
Integration credentials
- When you connect an integration, the access token, API key or signing secret it uses is encrypted before it is stored, with a key kept in our application's secret store and never in the database.
- After you save a credential, the dashboard shows only its last four characters. The full value is never sent back to a browser, and the database roles that serve your dashboard and the assistant can't read the encrypted column.
- Sign-in tokens for knowledge sources you connect are encrypted by our application before they reach the database.
- API keys for our public API are shown once, when you create them. We store only a one-way hash, so a key can't be recovered, only revoked and replaced. Webhooks we send you are signed, so you can check they came from us. Rolling out
Roles and access
Each workspace has four roles. The application checks them on every page and request, and the database enforces them again wherever it can see who is signed in. Rolling out
- Owner: Everything, including billing, phone numbers and other owners.
- Admin: Everything except managing owners: team, integrations, billing and the audit log.
- Agent: Works the inbox: replies, takes conversations over, fixes answers and exports.
- Viewer: Read-only. Sees conversations and reports; cannot reply, approve, export or change settings.
- Owners and admins always see every brand in the workspace. An Agent or a Viewer can be limited to chosen brands, and the database hides the rest.
- Nobody can change their own role, an admin can't change an owner, and the last owner can't be removed.
- Our internal admin tools are limited to named AnswerTide staff accounts, and they don't bypass the database's workspace fences.
Two-factor sign-in
Each team member can turn on two-factor sign-in with an authenticator app. Rolling out
- It is optional for each person. We recommend it for owners and admins.
- Once it is on, the dashboard stays locked until the second step is passed.
- You get ten one-time recovery codes. We store only a one-way hash of each code.
- Five wrong codes in a row lock the second step for 15 minutes. A code can't be used twice.
- Owners and admins can see who has it on. An owner, or an admin for anyone but an owner, can reset it for a teammate who lost their device.
Audit log
Owners and admins can read and download a log of who changed what. Rolling out
- It records team and role changes, invites, integrations connected or removed, API keys and webhooks, plan and spending-limit changes, assistant settings, pinned answers, corrections, approvals, conversations taken over, two-factor changes and data exports.
- Entries can't be edited or deleted. The log is kept as long as the workspace.
- Entries never contain passwords, tokens, keys or codes. Settings changes record which setting changed, not its value.
Keeping workspaces apart
- Every workspace's data is fenced off in the database itself (row-level security, switched on and enforced for every workspace table), so one workspace's requests can't read another's.
- The assistant on your site uses its own restricted database role. It can't read your dashboard data.
- The web application never holds the database credential that can skip these fences. Only our background content importer uses it.
- Automated tests check on every change that one workspace can't read or write another's data.
Content we don't trust
- Imported pages, emails and other incoming text are treated as data, never as instructions to the assistant.
- Actions and webhooks that call an address you give us accept only public HTTPS addresses, never private or internal network ones. Integrations call only their provider's own domain.
Certifications
AnswerTide doesn't hold third-party security certifications such as SOC 2 or ISO 27001. We answer security questionnaires honestly.
Report a security issue
Email security@answertide.com. Include steps to reproduce, and give us a reasonable chance to fix the issue before you share it publicly. Service incidents are posted on the status page.