Refleks

Security at Refleks

Practical safeguards for your content and visitors

Refleks is designed to keep each customer's data separated and to limit what the embedded widget can access on a customer website.

Account and tenant isolation

Account sessions are stored server-side, passwords are salted and hashed, and owner-facing database queries are scoped to the authenticated account.

Isolated website widget

The chat interface runs inside a sandboxed Refleks-origin iframe. Signed visitor sessions are bound to a site, and API requests validate the connected website origin.

Payment separation

Paddle is the merchant of record and processes payment details. Refleks does not store full card numbers or full billing addresses.

Abuse and cost controls

Authentication, crawling, chat, and AI-provider usage have server-side limits. Production health checks verify the database, worker, configuration, and deployed release identity.

Report a security concern

Send the affected URL, a clear description, and reproduction steps. Please avoid accessing data that is not yours or disrupting the service while testing.

Email support@refleks.dev

For details about collected data, retention, and service providers, read the Privacy Policy. Refleks does not currently claim a third-party security certification or a contractual uptime SLA.