Security & trust

Automation with
deliberate boundaries.

HyperChat is designed so useful automation does not require unrestricted authority. Permissions, credentials, tenants, crawling and deployment each have their own server-side gate.

Hashed API credentials

Project and agency keys are generated from cryptographic randomness, returned once and stored only as keyed hashes. They are scoped and revocable.

Signed delivery

Webhook bodies are signed with HMAC, include a timestamp and idempotency key, and use durable retry records for safe downstream processing.

Tenant isolation

Agency API queries require the authenticated agency ID as a server-side condition. A different tenant receives a not-found response.

Website authority

Agency builds require a recorded attestation plus DNS, well-known file or internal contract verification before crawling begins.

Crawler restrictions

The HyperChat crawler identifies itself, honours robots.txt, rejects private-network targets and refuses redirects outside the authorised hostname.

Human release gate

Agency-generated chatbots finish in review state. Deployment is separate, audited and requires current verified domain authority.

Consent-aware leads

Lead capture requires visible consent, stores the wording accepted and links the visitor directly to the relevant privacy information.

Cost and abuse limits

Per-route request limits, project quotas, monthly answer allowances and bounded scraping prevent one workload from consuming uncontrolled resources.

Audit history

Authority, build, configuration, deployment, credential and integration actions create tenant-scoped records for investigation and accountability.

Responsible disclosure

Found a security issue?

Please avoid accessing customer data or disrupting service. Send a clear description, affected URL and safe reproduction steps to Clone Centre. We will acknowledge and investigate valid reports.

Report securely by email