Access and role controls
Workspace access is authenticated and actions are checked against the signed-in account. Pro workspaces can invite up to two operator accounts. Those invited operator accounts have limited team-management capabilities; the workspace owner remains responsible for adding or removing them.
Passwords are stored as password hashes rather than readable passwords. Password reset flows use time-limited verification, and team invitations are time-limited. Session cookies are configured with HTTP-only and SameSite protections, with secure cookies when HTTPS is in use.
AI safeguards
Beaco is designed to ground business answers in connected website knowledge, workspace instructions and other operator-provided knowledge. The AI is instructed not to invent business prices, policies, guarantees or factual claims when verified information is unavailable.
- Human takeover stops automatic customer-facing AI replies in that conversation.
- Operator AI assistance remains private until the operator chooses to send a response.
- Direct AI instructions can be temporary or persistent and can be stopped by the workspace operator.
- Knowledge gaps can be surfaced for operator review instead of silently becoming invented answers.
Data controls
Conversation, visitor and website-intelligence data is separated by workspace identifiers in the application data model. Operators can delete visitor intelligence according to available controls. When a Pro operator removes a conversation from the Inbox, Beaco may retain a protected audit copy for platform integrity and administrative review as disclosed in the Privacy page.
Platform administration
Authorized Beaco platform administrators have controls for account safety, plan administration, abuse review and protected audit history. The Beaco-owned system workspace is protected from ordinary suspension or deletion actions so the public Beaco experience is not accidentally disabled.
Secure deployment is shared work
Production security also depends on the environment in which Beaco is deployed. Workspace owners and platform operators should use HTTPS, protect server and email credentials, keep software current, restrict hosting access, and avoid placing API keys or passwords in client-side code.
Security should be treated as an ongoing operational process, including monitoring, updates, access reviews and appropriate backups.