Security & Privacy
DeskClone AI handles your customers' support conversations, your knowledge base, and your connected tools. Here is exactly how that data is protected - every claim on this page reflects what is live in the platform today.
Encrypted everywhere
All data is encrypted in transit with TLS and at rest - the database, file storage, and backups. Backups run automatically every day on a rolling window.
Scrubbed before the AI sees it
If a customer pastes a card number, SSN, or API key into chat, it is redacted before it is stored and before any AI model reads it - on every message, with no setting to get wrong. Outbound responses are scanned too, and anything shaped like a leaked secret is redacted from the stream.
Each customer is an island
Your agents, conversations, knowledge, and connections are scoped to your account on every query, and an adversarial isolation test suite must pass before every release. Knowledge files are private by default - only files you explicitly mark public can ever reach your chat widget.
Connected accounts stay locked down
Credentials for the tools your agent uses - Shopify, Stripe, Zendesk, email inboxes, and the rest - are encrypted in the database and never exposed to the AI model. Our servers attach credentials only at the moment of the API call.
Customer chats can look, not touch
By default, website visitors' chat sessions use read-only tools. Write actions like refunds or order edits are unavailable to the model unless you enable them - and then they run behind hard, server-enforced limits (maximum amounts, required fields) that prompt trickery cannot override. Every tool action lands in an audit log you can review.
Prompt injection is expected, and handled
Every inbound message is screened against known injection patterns - instruction overrides, role hijacks, prompt extraction. Agents with higher-risk tools automatically run in blocking mode, and attempts are logged to a security event stream you can see.
Our commitments
Your AI never trains on your data
Conversations and knowledge are processed by leading AI providers (OpenAI, Anthropic, AWS Bedrock) under their business API terms: your data is not used to train their models, and provider-side retention is limited to short abuse-monitoring windows.
Where your data lives
All customer data is stored on AWS in the US region, encrypted at rest. The production database is not reachable from the general internet - access is network-restricted, password-protected, and TLS-enforced.
Deletion and retention on your terms
You can export or permanently delete an individual visitor's conversation data on request, and set your own retention window for conversation data - enforced automatically, including stored file uploads. When you leave, your data goes with you.
Responsible disclosure
Found a vulnerability? Report it to security@deskclone.ai. We acknowledge reports within two business days, keep you informed through triage and fix, and credit researchers who want credit.