Security
This page is written in French. The English and Spanish versions are courtesy translations: if they differ, the French version prevails.
Written for the person who has to approve the tool, not for the one who buys it. What is already true is written in the present tense. What isn't true yet is written down too.
Where the data lives
At Google Cloud, in Firestore. Conversations, visitors and each site's configuration are in a database dedicated to Krealo Chat, separate from the agency's other products.
Attached files — a photo of an appliance, an invoice — are in Cloud Storage and are never served from a public address: every opening goes through a signed link that lasts one hour. The link travels in the browser's address bar and ends up in a history or a screenshot; what needs to last is the file, not the link.
Every night, a full copy of the database is exported to a separate Google Cloud storage space. Each copy is kept for 30 days, then deleted automatically. Attached files are not part of this copy.
Who can access it
Firestore's rules deny everything by default. Each collection declares who can read and write, and nothing that isn't declared is accessible — including to us from a browser.
Whether an agent belongs to a workspace is read from the database, not from their token: removing access takes effect on the next request, not within the following hour. That's the difference that matters the day someone leaves the team.
The visitor to your store doesn't have an account. Their session is anonymous and can only read their own conversation.
Secrets
No key is in the code. They live in Google Secret Manager and are read at run time. Your Shopify store's token is encrypted and tied to your workspace: it is never sent back to the browser, not even yours.
What is verified, not just declared
Shopify and Meta webhooks are validated by signature, computed on the bytes received. Uploaded files are checked by their first bytes, not by what the browser declares: someone can say "it's an image" and send something else.
What happens is logged with the identifier of the customer, the conversation and the site — never with the content of a message, an email or a phone number. Logs are seen by more people than the database.
What isn't done yet
We write it down because a security page that only lists virtues isn't believable, and rightly so.
There is no separate test environment yet
Deployments go straight to production. It's the biggest risk on this list and it's the one we're working on first.
The browser content security policy is in report-only mode
It is declared and monitored, but it doesn't block anything yet. A poorly calibrated policy breaks the console instead of protecting it, so we look at what it reports before turning it on.
We don't have SOC 2 or ISO 27001 certification
We're a small team in Montréal. If your organization requires it, we're not the right choice today, and we'd rather tell you here than after three meetings.
If something happens
Quebec's Law 25 requires us to notify you of a confidentiality incident that presents a serious risk. We will, and we'll publish what happened.
A question this page doesn't cover? Write to us in the bubble at the bottom right: we're the ones who answer.