Skip to content

Security

Last updated

In short

DashDesk isolates every workspace with Postgres row-level security, encrypts channel credentials with AES-256-GCM, verifies Meta webhook signatures on every request, and hosts its API in Frankfurt. It holds no audited certification today — no SOC 2, no ISO 27001, no HIPAA attestation — and this page says so rather than implying otherwise.

Which certifications does DashDesk hold?

None. DashDesk has not completed a SOC 2 audit, an ISO 27001 certification or a HIPAA attestation, and has not been through an independent GDPR audit. If your procurement process requires one of those reports today, DashDesk cannot satisfy it, and no amount of describing the controls below changes that.

The reason this page leads with the gap is that the alternative is worse. A trust page that implies an audit it has not had is the one claim a buyer can check in five minutes, and failing that check costs more than the missing certificate does.

What follows is a description of how the system is actually built, which is a different and weaker claim than an audited one — verified by reading the code and the database policies, not by an auditor.

How is one workspace isolated from another?

By Postgres row-level security on every tenant table, not by a filter in application code. Each query runs as the signed-in user, and the database refuses rows belonging to another workspace even if the API asks for them — so a bug in a route handler cannot leak another tenant's conversations.

The three roles — Admin, Team Leader and Agent — are enforced by the same policies. A permission that is hidden in the interface is also denied at the database, which is the only version of a permission that means anything.

How are channel credentials stored?

Encrypted at rest with AES-256-GCM, using a key held in the deployment environment and never in the database. Access tokens for WhatsApp, Instagram and Messenger are decrypted only at the moment an outbound request is signed, and are never returned to the browser.

Inbound Meta webhooks are verified against the app secret on every request, so a forged payload claiming to be a customer message is rejected before it reaches the inbox.

Where is data hosted?

The API and its realtime gateway run in Frankfurt, Germany. Postgres is hosted on Supabase. Message text is sent to the configured AI provider — Groq or xAI — for triage and draft replies, and is not used to train models.

Conversation history belongs to the workspace and is exportable by an Admin. A plan change never deletes it.

  • Row-level security on every tenant table in Postgres
  • Channel credentials encrypted at rest with AES-256-GCM
  • Meta webhook signatures verified on every inbound request
  • API and realtime gateway hosted in Frankfurt, Germany
  • Roles enforced by database policy, not by the interface
  • Audit log of workspace activity on the Scale plan

Frequently asked questions

Is DashDesk SOC 2 certified?
No. DashDesk has not completed a SOC 2 audit. It also holds no ISO 27001 certification and no HIPAA attestation, and has not had an independent GDPR audit.
Is DashDesk GDPR compliant?
DashDesk is built for GDPR obligations — EU hosting, encryption at rest, per-workspace data isolation and Admin-initiated export and deletion — but it has not been independently audited, so it describes its controls rather than claiming certified compliance.
Does DashDesk use my conversations to train AI models?
No. Message text is sent to the configured model provider to classify a message or draft a reply, and is not used to train models.
Can I delete customer data on request?
Yes. An Admin can delete a customer and their conversation history from the workspace, which removes it from the database rather than hiding it from the interface.
How do I report a security issue?
Email support@contact.dashdesk.ahmedsherifnabhan.online with the details. Reports are read directly by the person who builds the product.

One CRM inbox. AI that actually replies.

Create a workspace, connect WhatsApp, and watch AI triage, reply to and log every customer automatically.

Free plan, no card required.

Try it free
Security and data protection at DashDesk