Security that matches a real support desk

Live chat carries names, emails, and sometimes payment confusion. ChatDix keeps that in the workspace that collected it, with roles and sign-in controls owners can actually use.

Workspace isolation

Chats, visitors, contacts, and projects belong to a workspace. Agents only see the workspace they were invited to. Super admin operators can manage the platform; they are not a substitute for your internal access policy. Do not share owner passwords. Invite seats instead.

Authentication

Email and password are stored as a hash, not reversible text. Google sign-in is available when the platform has OAuth configured. Optional two-factor authentication adds an authenticator code at sign-in. You can review sessions from security settings and sign out other devices.

Roles

Owners control billing, projects, and who is on the team. Agents handle conversations. Suspended users cannot sign in. That is the access model — short on purpose, so it is enforceable.

Widget and visitor data

The snippet talks to your ChatDix API for that project. Page URL, device, and messages are processed to deliver the chat. We do not sell visitor lists. See the privacy policy for retention and rights. You are responsible for a privacy notice on sites where you embed the widget, especially if you collect email in the panel.

Payments

Card and PayPal run on those providers. Bank and crypto references are stored so a reviewer can match a transfer. Never send card PAN data to ChatDix support mail.

Report an issue

Email hello@chatdix.com with “Security” in the subject. Include steps, not secrets in the first message if the inbox might be forwarded.