AshéAshé

Security at Ashé

Your business data — and your customers' conversations — deserve real protection. Here's plainly how we keep it safe.

Your data is isolated from every other business

Ashé is multi-tenant, which means many businesses share the same platform. The single most important thing we do is make sure that no business can ever see another's data. Every table in our database enforces row-level security, so your agents, conversations, customers, and knowledge bases are only ever accessible to your own account and the teammates you invite. This isolation is enforced at the database layer — not just in the app — so it holds even if a bug slips through elsewhere.

Everything is encrypted, in transit and at rest

All traffic to and from Ashé runs over HTTPS/TLS, so data moving between your browser, our servers, and your customers is encrypted end to end. Your data stored in our database is encrypted at rest by our infrastructure providers. You never have to configure any of this — it's on by default for every account.

Strong authentication, with optional two-factor

Accounts are protected by industry-standard authentication. Passwords are never stored in plain text — they're salted and hashed with bcrypt — and we actively block passwords that are known to have appeared in past data breaches. You can add two-factor authentication (2FA) to your account in Settings, requiring a one-time code from an authenticator app on top of your password.

We never store your payment details

All billing is handled by Stripe, a PCI-certified payments provider. Your card number never touches Ashé's servers — it goes directly to Stripe. That means the most sensitive financial data in the system is never ours to lose.

Built on trusted infrastructure

Ashé runs on Supabase and Vercel — the same infrastructure used by thousands of production applications. We keep our software and dependencies up to date, patching known vulnerabilities promptly, and we monitor for security advisories on an ongoing basis.

You stay in control of your data

You can export or permanently delete a customer's data at any time from within the app, giving you the tools to honor privacy requests under regulations like GDPR and CCPA. When you delete data, it's removed — not just hidden. If you ever leave Ashé, your data leaves with you.

Honest about where we are

Security is never "finished," and we'd rather be straight with you than overstate. Ashé is a young platform: the protections above are real and in place today, and we're continuing to invest in independent security testing and formal compliance as we grow. If your use case involves highly sensitive or regulated data, we're happy to talk through specifics before you commit.

Reporting a vulnerability

If you believe you've found a security issue, we want to hear from you. Please email security@asheagents.com with the details, and we'll respond as quickly as we can. We appreciate responsible disclosure and won't pursue action against good-faith researchers.