1. Security approach
Security is part of the WI SuperChat product design. We combine technical, operational, and organizational measures to protect accounts, sessions, user content, billing flows, AI workflows, files, images, and public pages.
2. Account and authentication protections
- Google sign-in and password authentication flows are designed to authenticate users securely.
- Session checks, token handling, and route protection help keep private pages private.
- Users should use strong passwords, keep Google accounts secure, and avoid sharing credentials.
3. Data protection controls
We use controls such as encrypted transport, role-based access patterns, separation between public and private pages, logging, monitoring, secure provider configuration, and careful handling of sensitive environment variables. Access to production systems should be limited to people and services that need it.
4. AI and file safety
AI, file, image, and artifact features may involve third-party providers. WI SuperChat is designed to route requests through controlled runtime paths, avoid exposing secrets, and limit processing to the user’s request where possible.
5. Vulnerability reporting
If you believe you found a vulnerability, contact support@wisuperchat.com. Do not publicly disclose technical details, access data that is not yours, interrupt service, or perform destructive testing. Provide clear steps, affected URLs, screenshots or logs, impact, and your contact email.
6. Incident response
If we detect a security incident, we will investigate, contain, remediate, document, and notify affected users or authorities when required by applicable law. Timing and content of notices may vary by region and incident severity.
7. User responsibilities
Security also depends on users: protect devices, update browsers, use strong credentials, review links before signing in, do not upload secrets unless necessary, and report suspicious activity quickly.
8. Limitations
No connected system is perfectly secure. This page describes a security baseline and is not a warranty that every attack, outage, or data incident can be prevented.
