Trust
Security
Fidibeki holds your customers’ words and your product’s context. Here is precisely how it is protected: no vague badges, just implemented behavior.
Audit trail for sensitive access
Every view and download of attachments, replay, exports, and other sensitive support data is logged with actor, timestamp, and purpose. We are building this so your team can prove who accessed what, and when.
Passwordless authentication
Sign in uses emailed magic links. There are no passwords to phish or leak. Sessions use brief tokens scoped to the audience and rotating refresh cookies with reuse detection. Token reuse outside a narrow rotation window revokes the entire session family.
Least privilege permissions
Workspace membership is governed by explicit per route permissions covering projects, widget rules, feedback, issues, sessions, members, API keys, integrations, and account operations. Invitations can be restricted to verified company email domains.
Quarantined upload pipeline
Attachments upload through brief presigned URLs and are verified for byte size and MIME type. Files land quarantined and only become visible after signature verification. Storage objects stay private. Downloads and replay playback stream through the authenticated API, never as direct storage links.
Encrypted integration secrets
Webhook secrets and custom headers are encrypted at rest with AES-256-GCM and displayed exactly once at creation. Outbound webhook deliveries are signed with HMAC-SHA256 so your systems can verify every payload.
Abuse resistant public endpoints
Public submission endpoints enforce per IP and per project rate ceilings, verify the browser origin against your allowed domains, and apply daily AI cost budgets. Limiter identities are brief HMAC hashes. Diagnostics never persist raw network or visitor data.
Last updated: 23 July 2026
This is the current version of the security page. Previous versions will be archived here when the page changes materially.
Infrastructure and access
Fidibeki runs on managed cloud infrastructure. We do not own or have physical access to the underlying data centers. Production access is limited to designated operators, uses multi factor authentication, and is logged. We deploy through an automated pipeline with required review, continuous integration, and dependency scanning.
Encryption and data protection
- All traffic between browsers, APIs, and integrations uses TLS.
- Integration secrets and webhook headers are encrypted at rest with AES-256-GCM.
- Object storage is private by default; direct links are never exposed to users.
- Session replay and attachment playback stream through the authenticated API.
Application security
- All code changes are reviewed before merging;
- Automated tests, linting, and vulnerability scanning run in CI;
- No production secrets are stored in source code;
- Error telemetry is scrubbed to avoid collecting PII or secrets.
Incident response and disclosure
We maintain an incident response runbook and an internal breach register that records incident facts, assessments, chronology, and containment behind a platform-administration boundary. For personal data breaches, we notify affected customer/controllers without undue delay, and what we owe you is set out in the Data Processing Addendum. To report a security issue or vulnerability, email us at [email protected]. Please include a proof of concept and do not test against customer workspaces or production data.
Certifications and compliance claims
Fidibeki does not currently hold SOC 2, ISO 27001, or similar certifications, and we will not imply otherwise. If your security review needs specific answers, questionnaire responses, or roadmap commitments, book a demo.
Have a security question?
Book a demo and bring your security checklist. We would rather answer it before you buy than after.