Security
Saluto handles live customer conversations. Here is exactly how we protect them — described plainly, with no certifications we don't hold.
Our approach
Saluto handles live customer conversations, so security is a product requirement rather than a policy document. This page describes the controls in place today. We would rather describe them plainly than claim certifications we do not hold.
Encryption
Traffic between your customers, the messaging platforms and Saluto is encrypted in transit using TLS. Conversation data and configuration are encrypted at rest by our hosting provider.
Note that end-to-end encryption on a platform such as WhatsApp terminates at the business endpoint — that is inherent to any business messaging tool, including ours.
Access control
Access to production systems is limited to the people who need it, protected by multi-factor authentication and reviewed when roles change or someone leaves.
Within your account, you decide who on your team can see conversations. Our staff access customer conversation data only where you ask us to — for setup, support or debugging — and that access is logged.
Data segregation and retention
Each customer’s configuration and conversations are logically separated. Retention follows your customer agreement; on termination we delete or return data within a reasonable period, subject to legal requirements.
Third parties
We rely on established providers for hosting, AI models and messaging APIs. Each is bound by contract to protect data, and we do not permit your end customers’ conversations to be used to train publicly available models.
We keep the list of subprocessors current and will share it with customers on request.
Resilience
Data is backed up regularly and restores are tested. Where a platform we depend on has an outage, conversations queue and are processed when service returns.
Reporting a vulnerability
If you believe you have found a security issue, email support@salutodesk.com with enough detail to reproduce it. Please give us a reasonable window to fix it before disclosing publicly. We will acknowledge your report and keep you updated.
We do not currently run a paid bug bounty, but we credit researchers who report responsibly and ask to be credited.
Incidents
If a breach affects your data, we will notify you without undue delay, describe what happened and what we are doing, and support any notifications you are required to make.
Questions from your security team
Happy to answer a questionnaire or walk your team through the specifics on a call — get in touch.
Last updated: 3 August 2026.