Skip to content

Trust center

Security

The controls currently used to protect customer workspaces, plus a clear statement of work that is not complete.

Last updated: July 20, 2026

Current safeguards

  • HTTPS protects application and provider traffic in transit.
  • Authentication, secure sessions, and account-scoped authorization limit access to workspace data.
  • Server-only service boundaries protect privileged operations and provider administration.
  • Customer-generated platform API keys are stored as non-recoverable hashes.
  • Hosting and database providers apply their own infrastructure, backup, and storage security controls.

Third-party integration credentials

Some integrations require recoverable access tokens or customer-supplied provider keys so the service can act on the customer’s behalf. These values are access-controlled and kept behind server-side boundaries, but a dedicated application-layer encryption and key-rotation system for all such credentials is not yet complete.

That work is deferred until the current interface migration is complete. Until it ships and is verified, we do not describe WhatsApp, Google Workspace, OpenRouter, or other recoverable third-party credentials as application-encrypted.

Customer responsibilities

  • Use unique passwords, protect email accounts, and remove access for people who leave your organization.
  • Grant integrations only the access needed and revoke connections that are no longer used.
  • Keep customer consent records accurate and avoid placing secrets in messages, templates, or knowledge sources.
  • Report suspicious account activity promptly.

Report a vulnerability

Send a clear description, affected route or feature, and reproduction steps to security@techupservices.in. Do not access other customers’ data, disrupt the service, or publish sensitive details before we can investigate.