Security
How Hushdesk protects your account, your team and your customers’ data.
Last updated 6 October 2026
Your support inbox holds your customers’ names, addresses and orders. This page explains how we protect them, in plain words.
Signing in
- Passkeys (Face ID, Touch ID, Windows Hello, security keys) for phishing-resistant sign-in.
- Two-step sign-in with an authenticator app, plus one-time recovery codes.
- Passwords are stored only as salted scrypt hashes, never in plain text.
- Sign-in links and codes expire in 15 minutes and work once.
- Sessions can be listed and ended from your account, and changing your password signs out every other device.
Keeping workspaces apart
Every record belongs to exactly one workspace, and every read and write is scoped to the workspace you are signed in to, so one store can never see another’s data.
Encryption
- All traffic is encrypted with TLS.
- Connection secrets for your apps (Shopify tokens, API keys) and two-step secrets are encrypted at rest with a separate key, and never shown again after you save them.
Least privilege, and a trail
- Workspace roles (owner, admin, agent, viewer) decide who can change settings and act on orders.
- Every change to users, settings and security is written to your workspace’s audit log.
- When Hushdesk support needs to look at your workspace to help you, they get a read-only view that cannot change anything, and the visit appears in your audit log.
AI safety
AI replies are checked before sending: anything mentioning a link, code or order number that is not in your data, or any upset customer, goes to a person instead.
Payment data
Card details are handled by Stripe or Shopify. They never touch our servers.
Reporting a vulnerability
If you find a security issue, email security@hushdesk.tech. Please give us a reasonable time to fix it before you share it. We will not take action against good-faith research that respects our customers’ privacy.