Skip to content
SECURITY & DATA HANDLING

Clear controls.
Honest boundaries.

Security claims should explain what is implemented. This page describes the current service; it is not an independent certification.

Agency access

Workspace APIs require sign-in and check account ownership when reading or changing agency records. Browser write requests are checked for the expected origin. The public widget key identifies an agency; it is not a secret password. Widget requests are checked against the connected website domain and service allowance.

Customer sign-in

The email/password integration delegates credentials to Supabase. Protected requests verify the user with the authentication provider. Session cookies are secure and HTTP-only. Registration requires email confirmation; reset links are checked by the provider, and submitting a new password signs out existing sessions. Account endpoints have origin checks and rate limits. The integration still requires provider configuration and live email testing before registration opens.

Payments

The integration uses a hosted payment-provider checkout. AgentReady does not collect card numbers in its own forms. Subscription access is updated from signed provider notifications, not from a browser’s payment-success URL. Paid checkout is currently disabled.

Visitor information

Messages and enquiries are stored in the hosted database. The widget keeps an opaque conversation identifier in session storage to restore the conversation during same-tab navigation. Enquiry source URLs omit query strings and fragments. Screening answers are self-reported; contact verification is not implemented.

AI and notifications

Relevant messages, agency information and listings may be sent to the configured AI provider. Optional Telegram bot tokens are encrypted in storage. Telegram alerts contain an event notice and workspace link, not visitor contact details. Delivery is best effort, with attempts visible in Settings.

Data controls

Agencies can export records, delete individual enquiries and conversations, and preview cleanup of old closed records. Automatic retention and a verified backup-restoration process are not currently provided as product guarantees.

Current limitations

No independent penetration test, security certification, multi-user role system or high-concurrency guarantee is claimed. AI answers can be incorrect. The agency remains responsible for checking listing facts and its visitor-facing privacy information.

Report a security concern

Use the security contact form. Describe the issue and affected page without including secrets or another person’s private records.