Home  ›  Security & KVKK
🔒 Security & compliance

Customer data is serious business — and we treat it that way

From multi-tenant isolation to encrypted sessions, from backups to KVKK compliance, we designed FlexInbox to protect your data.

Security measures

🏢

Multi-tenant isolation

Each company's data is logically separated; one org cannot access another's data.

🍪

httpOnly cookie sessions

The session token is kept in a cookie closed to JavaScript; short-lived access plus a renewable refresh token.

🔑

Strong authentication

Passwords are hashed with bcrypt; a password policy and session revocation (tokenVersion) are enforced.

🚦

Rate limiting

Rate limits on login and API endpoints against brute-force/abuse.

🔐

Encrypted transport

All traffic over HTTPS/TLS; security headers (HSTS, nosniff, etc.) enabled.

💾

Automatic backups

The database and sessions are backed up regularly; a recovery plan is in place.

You own your data

The business using the platform is the owner of its own customer data; FlexInbox acts only as a data processor, processing that data on the business's instructions solely to provide the service. We do not sell your data for marketing.

Unauthorized access is blocked with webhook verification, authorization checks and org-based query filters. You can clearly find which data we process, and for what purpose, on the Privacy Policy and Data Protection Notice (KVKK) pages.

  • KVKK & GDPR: Processing purposes, legal basis and your rights are documented.
  • Access control: Admin/agent roles and per-line authorization.
  • AI data: Only the necessary content is sent to the model provider for an AI reply; the knowledge base is yours.

Security — FAQ

Who are my conversations shared with?

Your conversations are shown only to your authorized agents. They are shared with third parties only to the extent necessary for the service to function (message delivery, CRM, AI reply, hosting).

Where is my data stored?

Message and media records are stored on our service servers and linked to the relevant CRM record. Some integration providers (Meta, Telegram, Zoho, Bitrix24, OpenAI) may process data abroad.

Are you KVKK compliant?

The data controller/processor role distinction, the disclosure notice and data subject rights are documented. We recommend consulting a legal advisor for your own business's VERBİS obligations.

What happens in a data breach?

Access logs are kept; in a possible incident, notification processes to affected parties and the authorities required by law are carried out.

Bring all your customer conversations into one panel

WhatsApp, Telegram, CRM and an AI agent — start free today, no credit card required.

Start Free →