Security & trust
Your customers’ conversations are safe with us.
LarkFlow handles your WhatsApp chats, quotations and customer data. Here is exactly how we keep each workspace separate, control who can do what, and record every change.
Tenant isolation
Every workspace’s data is walled off from every other workspace — in the database and in the API.
- Row Level Security is enabled on every table. Database rules only return or change rows that belong to your own workspace.
- Every API request is tied to your workspace on the server; IDs from another workspace are refused, not just hidden.
- Public endpoints (website chat widget, forms, landing pages) can only add data to the workspace that published them.
- Webhooks from WhatsApp (Meta), payment providers, CRMs and email are accepted only with a valid cryptographic signature.
Access control
Each team member gets a role, and the role decides what they can see and change.
- Roles: Owner, Admin, Manager, Agent, Sales, Finance, Support and Viewer.
- Viewer is read-only — enforced on every change in the API and again by the database, so it can’t be bypassed from the browser.
- Sensitive actions (billing, publishing, team and channel settings, the audit log) are limited to owners and admins.
- Email verification is required before anyone can use a workspace; removing a member revokes their access immediately.
Audit log
Owners and admins can see who changed what, when and from where.
- Every change — create, update, delete — is recorded with the person, the time, the record, the IP address and the browser.
- Covers changes made through the app and API, including changes made directly from the browser.
- Only the names of changed fields are logged, never their values, so passwords and tokens never end up in the log.
- Entries can’t be edited or deleted by anyone in the workspace. Filter by action, area and date, and export to CSV.
More protections
Encryption
All traffic uses HTTPS (TLS). Data is encrypted at rest by our database provider. WhatsApp, CRM, ERP and integration credentials are additionally encrypted with AES-256-GCM before they are stored.
Secrets stay secret
Access tokens and API keys are never shown back in the app or sent to AI models. AI features only see the data needed for the task you asked for.
Web protections
Strict Content Security Policy and security headers, rate limiting on the API and public endpoints, and spam protection on public forms.
Your data, your control
Export your data, and request deletion of your workspace at any time. Contacts can opt out of WhatsApp messages with STOP.
Infrastructure
Hosted on established cloud providers (Vercel, Render and Supabase) with managed backups and isolated production environments.
AI with guardrails
AI agents work inside your rules: approval steps for quotes and pricing, read-only roles respected by the AI assistant, and every AI action logged.
Security questions or a vendor questionnaire?
We’re happy to answer security reviews and procurement questionnaires. To report a vulnerability, please email us — we respond quickly and don’t take action against good-faith research.
Contact security team