Trust
Security at ConverseOne
Customer conversations are sensitive. We build security into the platform from the ground up, with layered controls, transparency and a commitment to continuous improvement.
Pillars
How we protect your workspace
These are the foundational controls that keep ConverseOne reliable and your customer data safe.
Encryption in transit and at rest
All data moving between your browser, our servers and third-party channels is encrypted with TLS. Data stored in our databases and object storage is encrypted at rest using industry-standard algorithms and key management.
Role-based access control
ConverseOne supports granular roles and permissions. Admins decide who can view conversations, edit CRM records, send campaigns, manage billing or change workspace settings. Access can be revoked instantly when someone leaves.
Infrastructure isolation
We run on cloud infrastructure designed for high availability and network isolation. Production environments are separated from development and testing. Databases are not exposed to the public internet.
Authentication and SSO
Accounts are protected by password-based sign-in with optional multi-factor authentication. Enterprise plans support single sign-on through SAML or OIDC, allowing teams to centralize identity management and enforce their own policies.
Audit logging
Key actions — logins, permission changes, message sends, automation edits and exports — are logged. Workspace owners and admins can review activity to understand who did what and when.
Vulnerability management
We run automated dependency scanning and static analysis in our build pipeline. External security assessments and penetration tests are conducted on a regular schedule. Findings are triaged and remediated promptly.
Security practices
- Secure development lifecycle
- Code review, linting and automated tests are required before any change reaches production.
- Least privilege
- Employees and systems only receive the minimum access needed to perform their roles.
- Incident response plan
- We maintain a documented response process with defined roles, communication steps and escalation paths.
- Backups and recovery
- Data is backed up regularly and recovery procedures are tested to ensure business continuity.
- Vendor review
- Third-party services are evaluated for security practices before integration and reviewed periodically.
- Employee training
- Team members receive security awareness training and are required to follow acceptable-use policies.
Responsible disclosure
If you discover a security issue in ConverseOne, please report it to security@converseone.com with enough detail for us to reproduce and address it. We ask that you do not publicly disclose vulnerabilities until we have had a reasonable time to respond.
For security questions or to request our latest security documentation, contact us at security@converseone.com.
Your customers are already talking.Bring every conversation together.
Connect your channels, automate repetitive work and give your team one complete view of every customer.