Developers
Security
How Callduck protects your data.
Security
Security is built into Callduck's foundations, from data isolation to webhook integrity.
Controls
- Tenant isolation — every record is scoped to its organization; webhook events derive their workspace from the channel, never from request input
- Role-based access control — Owner / Admin / Manager / Agent / Viewer (see Team roles)
- Credential handling — provider credentials are stored server-side and never sent to the browser
- Webhook signature verification — when an app secret is set, incoming payloads are verified against
X-Hub-Signature-256and rejected on mismatch - Hashed passwords & validated inputs — passwords are hashed; inputs are validated server-side
- Audit logging — significant actions are recorded for accountability
Shared responsibility
> Callduck secures the platform; you secure your credentials and secrets. Keep access tokens, app secrets, and your verify token private, and rotate anything that leaks.
تذكير: تبدأ كال داك في الوضع التجريبي الذي لا يرسل رسائل حقيقية. اربط بيانات اعتماد منصة واتساب للأعمال الرسمية الخاصة بك للانتقال إلى التشغيل الفعلي.