Security approach
DeskXP operates ugnAI using security controls built around workspace isolation, least-privilege access, managed infrastructure, protected credentials, server-side authorization, and operational monitoring.
1. Platform controls
- Encrypted HTTPS/TLS connections.
- Authenticated workspace access and role-based authorization.
- Backend validation of workspace membership and permissions.
- Database row-level security for workspace-scoped information.
- Server-side handling of administrative and AI credentials.
- Private storage and time-limited access where supported.
- Logging and audit records for important platform activity.
- Managed hosting, database, and cloud infrastructure.
2. AI and integration security
- AI service credentials are not exposed to browser clients.
- Only relevant context should be sent for AI processing.
- Connected-channel credentials are limited to authorized use.
- Webhook and integration requests are validated where supported.
- AI stops responding after configured human handoff states.
3. Customer responsibilities
- Use unique passwords and protect administrator accounts.
- Invite only authorized users and remove access promptly.
- Review connected channels and permissions regularly.
- Do not store passwords, OTPs, complete card details, or banking login credentials in ugnAI.
- Report suspected unauthorized access without delay.
4. Incident reporting
Suspected vulnerabilities, compromised credentials, or security incidents involving DeskXP or ugnAI should be reported to privacy@deskxp.com.
Include a clear description and supporting details, but do not send passwords, private keys, tokens, or personal information that is not necessary for investigation.
5. No absolute guarantee
No online system can guarantee absolute security. DeskXP reviews and improves its controls as ugnAI, its supporting infrastructure, the threat environment, and customer requirements evolve.
