01
Security
How dlogify handles your data.
- Redaction before storage
- The engine masks personal data such as email addresses, tokens and card numbers in messages and attributes before a sample, ticket or summary is written.
- Retention by plan
- Error samples, tickets and INFO summaries are deleted after 7, 30 or 90 days depending on the plan.
- Tenant isolation
- Every tenant-owned table is protected by PostgreSQL row-level security. Each service connects with its own role and can only reach the data it needs.
- API keys
- Keys are shown once and stored as hashes. A key can only ingest; it cannot read data or manage the account.
- Signed webhooks
- Every webhook delivery is signed with HMAC-SHA256 using a per-channel secret, which is stored encrypted and shown once.
- Webhook destinations
- Webhook URLs must use https and resolve only to public addresses, so a channel cannot reach internal networks.
- Subprocessors
- AI classification and ticket writing go through OpenRouter to the configured models. Email is delivered by Resend.