Security

How we handle your data.

Written for the person who has to sign off on us. No claims we cannot back up.

Infrastructure and encryption

  • The application runs on managed edge infrastructure with automatic TLS. All traffic to HeySale is HTTPS only.
  • Customer data is stored in a managed Postgres database with encryption at rest and encrypted backups.
  • Secrets and API keys are held in an encrypted secret store and are never committed to source control or exposed to the browser.

Access control

  • Every account's data is isolated at the database level with row-level security, so one customer cannot read another customer's salespeople, conversations, or leads.
  • Team members are invited by email and hold explicit roles. Permissions are checked on the server on every request, never in the browser, so nothing can be unlocked by editing the page.
  • Sensitive account actions — changing a salesperson, taking one live, inviting or removing a team member, and billing changes — are written to an append-only audit log visible in the dashboard under Activity.
  • Ownership of a salesperson created on your behalf by an AI assistant transfers only through a single-use claim link that expires, and the transfer is recorded.

Embed and website security

  • Your embed key only works on domains you have explicitly added and verified. A copied key pasted on another website will not start a conversation.
  • The widget runs in an isolated frame and only accepts messages from origins we verify, so it cannot read or be driven by the rest of your page.
  • You can see where your salesperson is actually installed, and remove a site or take a salesperson offline at any time from the dashboard.

API keys and AI connectors

  • Our connector for AI tools and assistants is a single authenticated endpoint. Every request must present an owner API key, and each key can only reach that owner's own salespeople.
  • Keys are shown once, stored hashed, and can be revoked immediately. Requests are rate limited and all input is validated.
  • Website addresses submitted for analysis are validated and restricted, so the connector cannot be used to reach private or internal networks.

Payments

  • Card details are entered directly with our payment provider and are never seen or stored by HeySale.
  • Payment notifications are cryptographically verified before anything is recorded, and billing events are written once and never edited in place.

What we collect from your visitors

  • Conversation transcripts, the page the conversation started on, and any contact details the visitor chooses to share.
  • Session duration, used to meter billable minutes.
  • We do not sell visitor data and we do not use your conversations to train third-party models.

Retention and deletion

  • Conversations and leads are retained for as long as your account is active so they stay available in your dashboard.
  • You can request deletion of specific conversations, leads, or your entire account at any time; we complete deletion within 30 days.
  • Billing records are retained as long as required for tax and accounting purposes.

Spend and abuse protection

  • Only spoken conversations cost money, and every spoken conversation is metered second by second. Typing is always free.
  • New spoken conversations are rate limited per visitor, per salesperson, and across the whole platform, with a ceiling on how many can run at the same time. A copied embed key on someone else's website cannot open a paid session.
  • Every account has a monthly limit per salesperson (US$100 by default) and can set an account-wide hard cap. When a limit is reached, spoken conversations pause and visitors can keep typing.
  • Spend alerts are on by default at US$100, US$250, and US$500 per month, and you can add your own amounts. We email you the first time your account passes each one.
  • Hard ceilings run before every spoken conversation starts, so they work at 3am without anyone watching: one visitor is limited to 25 spoken minutes an hour and 60 a day, one salesperson to 180 minutes an hour, and one account to 400. Cross any of them and spoken conversations stop automatically, including any call already in progress.
  • Every 15 minutes we compare each salesperson's last hour against its own normal pattern. Repeat traffic from one visitor, instant-exit bursts, and traffic from unapproved websites take that salesperson off spoken conversations for three hours and email you. Typing keeps working the whole time, so real visitors still get answers and you still get leads.
  • You can set your own account-wide monthly cap in Billing, and resume any paused salesperson yourself once you've reviewed the activity.
  • A platform-wide daily ceiling stops all new spoken sessions if total spend across HeySale ever runs away, so no bug or attack can produce an unbounded bill.

Availability and incidents

  • Agents fail safe: if a provider is unavailable, the agent stops rather than serving a broken or unbilled session.
  • A watchdog runs every minute and force-ends any session that stops reporting in, so a dead browser tab can never keep billing.
  • Security issues can be reported to security@hey.sale. We acknowledge reports within two business days.

Compliance status

  • HeySale is an early-stage company. We are not SOC 2 certified today; the controls above describe what is actually in place.
  • A Data Processing Agreement is available on request for customers in the EU and UK.