Account and billing
Security and privacy
How Sela protects your workspace: sign-in, tenant isolation, roles, verified customer identity, signed webhooks, encrypted secrets, and how to delete your data.
Last updated: 2026-09-29
This page explains, at a high level, how Sela keeps your workspace and your customers' data separated and protected, and what you can do to secure your own account. It describes controls in the product. It is not a compliance certification, and Sela does not claim any on this page.
Sign-in and organizations#
- Team members sign in through secure sign-in. Each workspace is its own organization, and everything in Sela is scoped to that organization.
- A signed-in person only reaches the workspaces they belong to. New members must be invited by an admin. There is no public directory of workspaces.
- Inactive members can be signed out automatically after a number of days you choose. See Settings and white-label.
- Creating a workspace is rate limited to 3 per hour per user.
Tenant isolation#
Every request is tied to one workspace, and that workspace is worked out in one place on the server. Records requested by id are checked against it, so an id from another workspace is reported as not found. Customer chat sessions are scoped to the session that created them, not to an email address, so a different device gets a different history.
In a business account, access to a branch requires a live grant, and removing a grant takes effect on the person's next request. See Multiple branches.
Roles and least privilege#
Roles decide what each member can do, from read-only viewers to owners. Sensitive actions, such as revealing full phone numbers and emails, exporting contacts, managing billing, exporting the workspace or offboarding it, have their own permissions. Customers' contact details are masked by default for roles that lack the reveal permission. A member can also be put on hold, which keeps them signed in but read-only. See Team, roles and permissions.
Roles in your workspace can never grant access to Sela's own internal operations tools, which use a separate sign-in.
Verifying your customers#
For websites that already know who the visitor is, the widget supports HMAC-SHA256 identity verification. Your server signs the visitor's email, a timestamp and your organization id with a secret only you hold. Sela verifies the signature with a constant-time comparison, accepts a timestamp within 5 minutes, refuses reused one-time values (nonces), and limits attempts to 5 per 15 minutes. You can also require verified sessions only. See Identity verification.
API keys, webhooks and secrets#
- API keys are shown once and only a hash is stored. Keys can have an expiry, a rate limit and narrow permissions. See REST API.
- Incoming provider webhooks, including Wayl payments, are accepted only when their signature verifies.
- Credentials you store for integrations are encrypted before they are saved.
- Data is transmitted over encrypted connections and protected at rest using the controls of the underlying infrastructure.
Webhooks that Sela sends to you follow the format described in Webhooks.
What the AI can and cannot access#
- The AI answers only as the assistant and business you configured. A workspace with no configured assistant is refused rather than answered under Sela's name. See Assistant identity and scope.
- It reads your knowledge base and the information tools you enable for the conversation. It works inside your workspace and cannot see other workspaces.
- Knowledge-base text cannot widen what the assistant is allowed to do. Actions such as changing an order or sending a payment link only happen through tools you turn on. See Tools and actions.
- Sela's AI is used only to answer your customers and to run the AI features you enable. Ask Sela support for details about data handling for your workspace.
Audit trail#
Sela records sensitive actions such as role changes, holds and offboarding, with who did them and why. Business accounts have an account audit page. There is no general audit-log page for single-location workspaces today.
Exporting and deleting your data#
Offboarding a workspace (owner or admin, with a reason of 3 to 500 characters, on the Scale plan or above):
- The workspace becomes read-only and integration credentials are disabled.
- A full export of your data is prepared for download.
- Your data is kept for a 90-day retention period, after which it is scheduled for deletion. Backups are purged within a 30-day window.
Data deletion request. There is no in-product delete button on other plans. A workspace owner or admin emails the support address shown on the Data deletion page, from the account email, with the subject "Sela data deletion request", the workspace name and ID, and whether to delete the whole workspace or only Meta integration data. Sela acknowledges the request, may ask you to verify it, and then deletes integration credentials, Meta links, messages, media, imported contacts and workspace settings. For WhatsApp Coexistence, disconnect in the WhatsApp Business app first.
The mobile app's account deletion is done from the profile settings in the app or from the web dashboard.
Free-trial abuse signals#
To prevent repeated free trials, Sela keeps device, network and channel signals for 90 days and then deletes them. Account and email eligibility history is kept longer so a trial cannot be reset.
Report a vulnerability#
Use the contact on the Sela Security page. Include steps to reproduce and do not access other customers' data while testing.
Practical checklist#
- Give people the lowest role that lets them work. Use viewer, agent, finance or manager before admin.
- Put departed staff on hold or remove them promptly.
- Keep API keys on your server and set an expiry and rate limit.
- Sign widget identities on your server and never expose the secret in browser code.
- Review who holds the admin role after any team change.
Can't find what you need? Contact support.