Security at Refleks
Practical safeguards for your content and visitors
Refleks is designed to keep each customer's data separated and to limit what the embedded widget can access on a customer website.
Account and tenant isolation
Account sessions are stored server-side, passwords are salted and hashed, and owner-facing database queries are scoped to the authenticated account.
Isolated website widget
The chat interface runs inside a sandboxed Refleks-origin iframe. Signed visitor sessions are bound to a site, and API requests validate the connected website origin.
Payment separation
Paddle is the merchant of record and processes payment details. Refleks does not store full card numbers or full billing addresses.
Abuse and cost controls
Authentication, crawling, chat, and AI-provider usage have server-side limits. Production health checks verify the database, worker, configuration, and deployed release identity.
Report a security concern
Send the affected URL, a clear description, and reproduction steps. Please avoid accessing data that is not yours or disrupting the service while testing.
Email support@refleks.devFor details about collected data, retention, and service providers, read the Privacy Policy. Refleks does not currently claim a third-party security certification or a contractual uptime SLA.
