Security
Last updated 26 September 2026
Visitors tell you about orders, accounts and problems. This page says plainly how that is held, and what we have not built yet.
Where the data lives
Writine runs on Amazon Web Services in the United States. The database is encrypted at rest and is not reachable from the public internet: only the application services inside the private network can open a connection to it.
Automated backups are retained for seven days so a bad day can be recovered from.
In transit
Every request is HTTPS. Certificates are issued and renewed automatically, and the services talk to the database with TLS verification rather than trusting the network.
Sign in and sessions
There are no passwords. You sign in with a single-use link emailed to your address, which expires in 30 minutes, so there is no secret to store, leak or reuse across sites. The session cookie is HttpOnly, so JavaScript on the page cannot read it, and you can revoke any session from Settings.
The link is held only as a hash, so a copy of the database cannot be turned back into a working link, and sign in attempts are rate limited per address.
Separation between workspaces
Each service owns its own database schema and connects with a role restricted to that schema, so one part of the system cannot read another's tables. Every request checks both that you are signed in and that the workspace you asked about is one you belong to.
The widget on your site
The widget loads in a sandboxed frame. It cannot read your page and your page cannot read the conversation. It answers only on the origins you list, so the snippet copied onto another domain gets nothing.
A visitor's credential is scoped to one conversation and expires within a day. It cannot read anything else in your workspace.
No AI, no training
Writine has no language models and no embeddings. Your conversations are not used to train anything, by us or by anyone else, because there is nothing to train.
Deletion
Deleting a conversation removes its messages and the notifications built from them. Deleting a workspace purges its chat and notification data. These are real deletions, not flags.
What we have not done yet
Writine is a young product and we would rather say so than imply otherwise. There is no SOC 2 report, no ISO 27001 certification, no formal penetration test and no bug bounty yet. There is no single sign on and no two factor authentication in the dashboard.
If any of those decides whether you can use Writine, tell us and we will give you a straight answer about timing.
Reporting a problem
Email privacy@writine.com with enough detail to reproduce the issue. We will confirm we received it, and we will not pursue anyone who reports a genuine vulnerability in good faith and gives us a reasonable chance to fix it.