Security at CallPilot
Security here is deliberately boring: isolate tenants, validate everything that crosses a boundary, and fail closed rather than guessing.
Tenant isolation
Every workspace is a separate tenant. Conversations, knowledge, appointments, and configuration are scoped to that tenant and are not shared across workspaces.
Widget protection
- Origin allowlists — production origin checking fails closed. Requests from origins a business has not allowed are refused.
- Visitor sessions — conversation continuation requires a visitor-session secret whose hash is persisted server-side.
- Rate limits — 30 messages per 5 minutes and 8 conversations per hour per IP on the public widget.
- Bounded input — message length is capped, and public errors are controlled; raw database and provider errors are never returned to a visitor.
Knowledge safety
Uploaded documents are size-bounded and MIME-restricted, validated server-side, and quarantined as drafts until a business approves them. Articles ground the AI rather than giving it unconstrained access.
Transport and sessions
Traffic is served behind TLS. Session cookies are HttpOnly and scoped to the deployment origin. The API emits CSP, HSTS, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy, COOP, and CORP headers.
Provider boundaries
Provider availability is checked and reported. When a provider is unavailable, the receptionist says so instead of degrading silently.
Reporting
Report security concerns via the contact page. We respond to credible reports and will not pursue good-faith research.