umwise.Back to site
Last updated · 17 July 2026

Security and reliability

Umwise is designed to keep customer data tenant-scoped, commercial actions inspectable and automation bounded by evidence. This page describes the controls in the production service; customer-specific commitments belong in the applicable agreement.

Identity and access

Workspaces use personal accounts, owner/admin/operator/viewer roles, revocable invitations and opaque server sessions. Passwords are protected with a memory-hard one-way hash, session tokens are stored only as hashes and administrative changes create audit events.

Data protection

Customer contacts, names and conversation bodies are encrypted with authenticated application-level encryption. Transport uses TLS, credentials stay server-side, integration secrets are encrypted at rest and protected environment files are readable only by the system administrator. Umwise does not expose stored secrets back to workspace users.

Integration boundary

Inbound webhooks require provider-native signatures or tenant-specific HMAC signatures and idempotency identifiers. Zadarma call events use the carrier signature and persist only one-way phone fingerprints; provider recordings are not fetched. Twilio OAuth uses server-only Client Credentials, one-hour access-token caching with an early refresh margin and read-only context-aware probes; access tokens and provider identifiers are not persisted or returned to the browser. Outbound delivery uses a durable queue with bounded retries. Inventory imports validate a strict contract and block local, private and metadata network destinations.

AI controls

Model output is schema-constrained and passes through a deterministic policy layer before it can affect a lead. Availability, price and payment state require connected-source evidence. Operator feedback, decision traces and daily multilingual regression evaluations make failures visible.

Operations and recovery

The service exposes separate liveness and database-backed readiness checks. Automated jobs process retries, connector synchronization, retention and regression evaluations. PostgreSQL backups are verified when created and restored into an isolated database every week. Optional encrypted off-site replication can be configured for a customer deployment.

Retention and portability

Workspace owners choose a retention period from 30 days to 10 years, subject to their agreement and legal duties. The daily maintenance job removes expired message, webhook and model-usage records. Owners can export operational workspace data without passwords, sessions or integration credentials.

Responsible disclosure

Please report a suspected vulnerability to [email protected] with reproduction details and impact. Do not access another user’s data, disrupt production or use automated destructive testing. We will acknowledge a valid report and coordinate remediation and disclosure in good faith.

Related documents

Privacy notice · Subprocessors · Website terms