SECURITY

Clear boundaries for every workspace and account.

Emozhuizhui applies server-side trust and account-scoped data access throughout its customer-support architecture.

Tenant isolation

Data access is scoped to a server-resolved tenant membership, not a client-supplied role.

Channel-account isolation

Multiple accounts on the same platform remain separate and are resolved before messaging operations.

Protected credentials

Connector credentials use application-level encryption and are not returned through standard interfaces.

HTTPS and browser sessions

Production traffic is served over HTTPS. Authentication uses server-side sessions and CSRF protection for browser write actions.

Verified webhooks

Provider signatures are checked before supported webhook events enter the messaging pipeline.

Human-controlled messaging

Outbound messages require an explicit human action and an unambiguous account target.

No automatic identity merge

Customers are not merged across platforms merely because names or order references appear similar.

Security contact

Report a suspected security issue to [email protected]. Please avoid including unnecessary customer data.

Emozhuizhui does not currently advertise a public bug-bounty program or external security certification.