From multi-tenant isolation to encrypted sessions, from backups to KVKK compliance, we designed FlexInbox to protect your data.
Each company's data is logically separated; one org cannot access another's data.
The session token is kept in a cookie closed to JavaScript; short-lived access plus a renewable refresh token.
Passwords are hashed with bcrypt; a password policy and session revocation (tokenVersion) are enforced.
Rate limits on login and API endpoints against brute-force/abuse.
All traffic over HTTPS/TLS; security headers (HSTS, nosniff, etc.) enabled.
The database and sessions are backed up regularly; a recovery plan is in place.
The business using the platform is the owner of its own customer data; FlexInbox acts only as a data processor, processing that data on the business's instructions solely to provide the service. We do not sell your data for marketing.
Unauthorized access is blocked with webhook verification, authorization checks and org-based query filters. You can clearly find which data we process, and for what purpose, on the Privacy Policy and Data Protection Notice (KVKK) pages.
Your conversations are shown only to your authorized agents. They are shared with third parties only to the extent necessary for the service to function (message delivery, CRM, AI reply, hosting).
Message and media records are stored on our service servers and linked to the relevant CRM record. Some integration providers (Meta, Telegram, Zoho, Bitrix24, OpenAI) may process data abroad.
The data controller/processor role distinction, the disclosure notice and data subject rights are documented. We recommend consulting a legal advisor for your own business's VERBİS obligations.
Access logs are kept; in a possible incident, notification processes to affected parties and the authorities required by law are carried out.
WhatsApp, Telegram, CRM and an AI agent — start free today, no credit card required.
Start Free →