Your clients' data is yours. Here is how we keep it.
This page lists only measures that are really working in Kweko today. Questions? Write to [email protected].
Every workspace kept apart
Each workspace's data is separated inside the database itself by row-level security. The app connects with a role that cannot bypass it.
- Every API route is tested automatically with attempts to reach another workspace: more than 300 routes, more than 3 000 probes
- Background jobs that span workspaces run on a separate, restricted connection
Encryption
Every connection is HTTPS only, with HSTS.
- Channel tokens, payment and telephony keys are stored encrypted
- Passwords are stored only as Argon2id hashes
- API keys are stored as hashes and shown once
- The session cookie is host-only, HttpOnly and Secure
Who sees what
Roles and permissions: owner, admin, team lead, manager and viewer.
- Viewers see client phone numbers and emails masked, in exports and the API too
- API keys: scopes, expiry, and an IP allowlist on Business
- Sign-in attempts are limited per IP and per account
Audit log
Security and admin events are written to the workspace's audit log: members and roles, API keys, integrations, exports, settings, deletion and support access.
- Visible to owners and admins
- Kept for 90 days, or 1 year on Business and Enterprise
Support access, under your control
Kweko staff can look into your workspace only through support access, and it follows strict rules.
- Staff record a reason first
- A one-time link is valid for 5 to 60 minutes
- They see it only as a viewer would: contacts masked, nothing can be changed
- The start and the end appear in your audit log
- Owners can turn support access off completely in settings
Backups
The database is backed up every night, and each backup is kept only after it is checked to read back.
- Backups are kept for 14 days
- An alert fires if the last good backup is older than 26 hours
Kweko AI only with consent
AI features are off by default. An admin turns them on by accepting a consent text; the consent, its version, who gave it and when are recorded.
- Phone numbers, emails and card numbers are masked before sending
- Consent can be withdrawn at any time
- Kweko does not use customer data to train AI models
Export and deletion
Download your data as CSV or Excel at any time, on the Free plan too.
- Deleting a workspace is scheduled 7 days ahead: owners can export or cancel in the meantime
- After 7 days every record of the workspace is removed for good, and from backups within 14 days
- A deleted account is anonymised at once
Where data is stored
The service's databases and backups run on our hosting provider's servers: [HOSTING PROVIDER], [DATA CENTRE LOCATION]. The full list of processors is in the Privacy Policy.
Found a vulnerability?
Please write to [email protected]. We review every report and reply. Do not test our security without our written permission.