AlwaysDesk

Security with Clear Boundaries

AlwaysDesk describes implemented protections and product boundaries without treating them as a compliance certification. Review the proposed call workflow, data, and contractual requirements before deciding it fits your business.

Protected web connections and server credentials

The production website uses HTTPS. Provider API credentials used by server-side workflows are kept on the server rather than placed in public page code. Public identifiers, such as a website analytics measurement ID or checkout client token, are distinct from secret API credentials.

Restricted administration

Internal administration is protected with Cloudflare Access and application-side authorization checks. Administrative responses are marked private and not for search indexing. These controls protect internal tools; they do not replace the review needed for a customer’s data-handling requirements.

Payment processing has its own boundary

Paddle handles checkout as Merchant of Record. The application verifies signed Paddle webhook messages before processing billing events, and separates sandbox and live billing records. AlwaysDesk does not claim its own PCI certification or ask you to put payment-card details into a reception or website chat conversation.

Website analytics is optional

Website analytics is activated only after consent on known public pages. Tracking excludes private onboarding and internal routes, and does not intentionally send chat text, form contents, email addresses, phone numbers, or URL query strings. The privacy page explains the website’s use of personal information and analytics.

Review call data for the proposed deployment

Discuss what information callers may provide, where summaries are delivered, which connected tools receive data, who has access, and the agreed retention and deletion arrangements. This page does not assert that all call records have a particular storage or retention policy.

Healthcare and legal businesses need separate privacy, professional, consent, security, and contractual review before processing sensitive information. AlwaysDesk does not claim HIPAA compliance, SOC 2, ISO 27001, independent penetration testing, or a compliance audit.

Use clear administrative limits

The AI should use approved information, confirm actual action results, and route questions outside scope to people. Do not share sensitive information in the public demo or website assistant. Contact the team to review your requirements; a product demonstration is not evidence of regulatory suitability.

Questions about this workflow

Is AlwaysDesk HIPAA or SOC 2 certified?

No such claim is made. Implemented controls are not a substitute for documented certification or deployment-specific review.

Should I put card information in chat?

No. Use the Paddle checkout flow for payment and keep card details out of website chat and reception intake.

Can healthcare or legal offices activate without review?

Sensitive-data use requires a separate review of applicable privacy, professional, security, consent, and contractual requirements.

Define your next front-office workflow

Review current plans or talk through your business rules and supported connections. Have a question? Use the AlwaysDesk chat button for product and pricing help.

Try the public call demo. It uses a fictional HVAC business to demonstrate the underlying front-office experience; no real HVAC service is provided.