1. Report a vulnerability
If you believe you have found a security issue in AlbTech Agents, email ledian@albtechsolutions.com with the subject "Security report". Please include:
- the affected URL or feature, and what an attacker could do;
- clear steps to reproduce, with screenshots or a short video if possible;
- how we can reach you for follow up questions.
We acknowledge every report within 3 business days and keep you updated until it is fixed.
2. Good faith research
We will not take legal action against research done in good faith that follows these rules:
- Test only against your own account and workspace. Never access, change or delete another business's data.
- Do not send messages to real WhatsApp users, and do not run denial of service or spam tests.
- Do not use social engineering or physical attacks against our team or clients.
- Give us reasonable time to fix the issue before telling anyone else about it.
In scope: agents.albtechsolutions.com and its APIs. Our machine readable contact is at /.well-known/security.txt.
3. How we protect data
- Every workspace is isolated in the database with row level security, enforced on every query.
- TLS on every connection. Data encrypted at rest. Meta access tokens encrypted with separate keys.
- Webhooks from Meta are verified with the app secret signature before they are processed.
- Staff access uses multi factor authentication, least privilege, and is written to the workspace audit log.
- Hosting in the European Union, with backups encrypted and overwritten on a rolling 30 day cycle.
- Personal data breaches are reported to affected businesses and authorities as the law requires. See our Privacy Policy.