Who can see my customers’ conversations?
+
Only members of your workspace, limited by their role and by the websites, Instagram accounts and mailboxes they have been given. IotaBot staff can enter a workspace only for support, for at most 30 minutes at a time, and each visit is logged.
Is there a Data Processing Agreement?
+
Yes. A workspace owner or admin can review and accept IotaBot’s DPA in the dashboard and download a signed copy.
How are connected account tokens stored?
+
Encrypted at rest with AES-256-GCM. API keys are stored only as hashes.
Can I restrict API access to my servers?
+
Yes. Each API key can carry an IP allowlist, and you are alerted when a key is used from a new network.
How do I verify a webhook really came from IotaBot?
+
Each delivery is signed with HMAC-SHA256 over a timestamp and the raw body using your endpoint’s secret. Verify the signature and reject old timestamps to block replays.
Can I get answers to a security questionnaire?
+
Yes — contact us with your questionnaire and we will answer it directly.