Security

Your data is protected at every layer.

instasupport is built with security and privacy as foundational requirements — not afterthoughts. Here is how we protect your merchant data.

Encryption at rest and in transit

All data is encrypted using industry-standard protocols. HTTPS is enforced on every connection. OAuth tokens are encrypted with ASP.NET Core Data Protection before storage.

Merchant-scoped access

Every workspace is isolated. Audit data, support tickets, analytics, and team settings are scoped to the merchant account that owns them. Cross-tenant access is architecturally impossible.

Input validation and sanitization

All user input is validated and sanitized before processing. HTML injection prevention, request body size limits (10 MB), and rate limiting protect against abuse.

Infrastructure security

The platform runs on containerized infrastructure with structured JSON logging, correlation IDs for request tracing, and Prometheus metrics export for monitoring.

Authentication and sessions

Secure password hashing with ASP.NET Core Identity. HTTP-only authentication cookies. Session tokens are never exposed to client-side JavaScript.

API and webhook security

CORS policies restrict API access to authorized origins. Webhook endpoints validate secrets before processing. API key authentication is available for programmatic access.

Our commitments

Security principles we follow.

All timestamps stored in UTC for global consistency
Audit trail logging for support operations and automation
Role-based access control: Owner, Admin, Agent, Viewer
Webhook secret validation on all inbound processing
Per-caller rate limiting to prevent abuse
No merchant data shared across workspaces

Get started today

Ready to turn storefront friction into growth?

Create your free workspace and run your first store audit in under two minutes. No credit card required.