Developers

Security

How Callduck protects your data.

Security

Security is built into Callduck's foundations, from data isolation to webhook integrity.

Controls

  • Tenant isolation — every record is scoped to its organization; webhook events derive their workspace from the channel, never from request input
  • Role-based access control — Owner / Admin / Manager / Agent / Viewer (see Team roles)
  • Credential handling — provider credentials are stored server-side and never sent to the browser
  • Webhook signature verification — when an app secret is set, incoming payloads are verified against X-Hub-Signature-256 and rejected on mismatch
  • Hashed passwords & validated inputs — passwords are hashed; inputs are validated server-side
  • Audit logging — significant actions are recorded for accountability

Shared responsibility

> Callduck secures the platform; you secure your credentials and secrets. Keep access tokens, app secrets, and your verify token private, and rotate anything that leaks.

تذكير: تبدأ كال داك في الوضع التجريبي الذي لا يرسل رسائل حقيقية. اربط بيانات اعتماد منصة واتساب للأعمال الرسمية الخاصة بك للانتقال إلى التشغيل الفعلي.

نبي نقيس أي الصفحات تفيد الناس. ما فيه كوكيز إعلانات، ولا بيع بيانات، ولا شي مربوط بهويتك. سياسة الخصوصية