Trust

Security at ConverseOne

Customer conversations are sensitive. We build security into the platform from the ground up, with layered controls, transparency and a commitment to continuous improvement.

Pillars

How we protect your workspace

These are the foundational controls that keep ConverseOne reliable and your customer data safe.

Encryption in transit and at rest

All data moving between your browser, our servers and third-party channels is encrypted with TLS. Data stored in our databases and object storage is encrypted at rest using industry-standard algorithms and key management.

Role-based access control

ConverseOne supports granular roles and permissions. Admins decide who can view conversations, edit CRM records, send campaigns, manage billing or change workspace settings. Access can be revoked instantly when someone leaves.

Infrastructure isolation

We run on cloud infrastructure designed for high availability and network isolation. Production environments are separated from development and testing. Databases are not exposed to the public internet.

Authentication and SSO

Accounts are protected by password-based sign-in with optional multi-factor authentication. Enterprise plans support single sign-on through SAML or OIDC, allowing teams to centralize identity management and enforce their own policies.

Audit logging

Key actions — logins, permission changes, message sends, automation edits and exports — are logged. Workspace owners and admins can review activity to understand who did what and when.

Vulnerability management

We run automated dependency scanning and static analysis in our build pipeline. External security assessments and penetration tests are conducted on a regular schedule. Findings are triaged and remediated promptly.

Security practices

Secure development lifecycle
Code review, linting and automated tests are required before any change reaches production.
Least privilege
Employees and systems only receive the minimum access needed to perform their roles.
Incident response plan
We maintain a documented response process with defined roles, communication steps and escalation paths.
Backups and recovery
Data is backed up regularly and recovery procedures are tested to ensure business continuity.
Vendor review
Third-party services are evaluated for security practices before integration and reviewed periodically.
Employee training
Team members receive security awareness training and are required to follow acceptable-use policies.

Responsible disclosure

If you discover a security issue in ConverseOne, please report it to security@converseone.com with enough detail for us to reproduce and address it. We ask that you do not publicly disclose vulnerabilities until we have had a reasonable time to respond.

For security questions or to request our latest security documentation, contact us at security@converseone.com.

Your customers are already talking.Bring every conversation together.

Connect your channels, automate repetitive work and give your team one complete view of every customer.