SECURITY

Sensitive support data deserves deliberate boundaries.

Helpeto is designed around isolated workspaces, encrypted secrets, narrow provider permissions, role-aware administration, and recoverable deletion. Security controls are part of the product workflow, not a hidden enterprise add-on.

support@north.studioG

SHARED INBOX

MC

Maya Chen

HLP-001248

Can I change my delivery address?

Open ticketAlex is viewing

Customer context, team activity, and reply history stay in one conversation.

Helpeto AI
AES-256-GCM encrypted secrets
Workspace-level tenant isolation
Private R2 attachment objects
01

SECRETS

Credentials are encrypted before database storage

OAuth refresh tokens, SMTP and IMAP passwords, and OpenRouter API keys are protected with authenticated encryption using the deployment's token encryption key. The interface never returns stored secret values in plaintext.

  • Unique nonce per encrypted value
  • Authentication tag detects tampering
  • Masked settings display
  • Disconnect removes channel access
02

TENANCY

Every operational query is scoped to a workspace

Tickets, contacts, channels, attachments, tasks, AI settings, members, and billing belong to a specific workspace. Membership and role checks run before changes, while platform administration is separately protected.

03

FILES

Attachments use private, tenant-prefixed object keys

R2 files are not published through a public r2.dev bucket. Downloads pass through authorized application routes, and permanent ticket or workspace deletion removes related objects so abandoned customer files do not remain indefinitely.

HELPETO

Connect a support channel without exposing the password to the team.

Give each agent an account, keep provider secrets encrypted, and retain control over every connection.

Start free