Skip to content

Trust center

Security without imaginary badges.

These are controls implemented in the product today. Chrishi does not claim an external security certification or audit that has not been completed.

Workspace isolation

Customer-owned records are scoped to their organization so one workspace cannot query another workspace's data through normal product paths.

Protected credentials

Connected-platform access tokens are encrypted at rest and are never displayed back in full. Deployment also checks credential status and expiry.

Secure transport

Public production domains use HTTPS. Internal service calls use authenticated requests where required.

Safer website reading

Submitted URLs are checked against private and local network ranges, expensive guest requests are limited, and fetched logo addresses are checked before download.

Monitoring with redaction

Application errors can be reported to Sentry when configured. Sensitive keys such as passwords, tokens, secrets, and authorization headers are removed from reports.

Traceable operations

Requests and background work carry identifiers so failures can be investigated without exposing credentials in ordinary logs.

Callback protection

Stripe, Meta, and selected internal or provider callbacks validate a signature or shared secret. Remote media downloads are checked before they are accepted.

Temporary preview cleanup

Unclaimed public website previews are isolated from other browser sessions and scheduled for deletion after 24 hours.

Least-claim policy

Chrishi does not claim SOC 2, ISO 27001, penetration-test, uptime, or regulatory certifications unless they are actually completed and published.

Report a security concern

Do not include passwords, access tokens, or customer content in your first message. Explain the affected area and how we can contact you securely.

Email security support