Security

Your tickets stay in your workspace.

Many customers share one Postgres database. Row-level security decides what a login may read. If the workspace is not set on the request, the query returns nothing.

Security settings for a workspace: active sessions, invites, and an API key.

One organisation per request

API calls set the tenant first. Public help looks up your slug, then reads only that knowledge base.

Keys and invites

Widget keys, invite links, and password-reset tokens are treated as secrets. Reset links expire.

Staging is closed

Our preview hosts ask for a password and tell search engines not to index them.

Sign-in

Google or email. TOTP if you want it.

People join through an invite. They can see their sessions and sign them out.

Questions

Common questions

Can another customer see our tickets?
No. Row-level security is on and forced. A request is tied to one organisation.
How do people on our team sign in?
Email and password, or Google. You can turn on TOTP. You can list sessions and sign them out.
Do you sell company-wide SAML?
Not in this version. The workspace uses Google or email, with one Google client for the platform.

Try it in a workspace you create.

Start a workspace
Security — workspace isolation · Xupport