//Legal

Security

Last updated: 29 July 2026. This page is maintained by Emelum to answer common security and privacy questions about ConvoSell. It describes the controls we operate today — it is not a certification or an independent audit.

Controls we operate

Encryption in transit

All traffic to the site and the platform is served over TLS. Integration credentials are transmitted over encrypted channels only.

Access control

Platform data is protected by row-level security policies. Administrative access follows least privilege and is limited to the personnel who operate the service.

Project-scoped isolation

Each customer workspace is scoped so that conversations, carts, and CRM records are readable only within that workspace.

Human approval on escalation

Actions that carry commercial or legal weight — refunds, exceptions, contested returns — are routed to a human before they are committed.

Audit trail of agent actions

Every automated action the agent takes is recorded with its trigger, the data it read, and the system it wrote to, so the sequence can be reconstructed.

Credential handling

Integration tokens for CRM and commerce platforms are stored as secrets, never in application code, and are revocable by the customer at any time.

Shared responsibility

Emelum is responsible for operating and securing the ConvoSell platform and the infrastructure it runs on. Customers are responsible for who they grant workspace access to, which third-party systems they connect, the accuracy of the data they send, and the policies their agents are configured to follow. End customers are responsible for the content they choose to share in a conversation.

Data handling

Conversation and order data is processed to deliver the service and is not used to train general-purpose models. Retention, sub-processors, and deletion commitments are set out in the Data Processing Addendum and the Privacy Policy.

Compliance posture

ConvoSell is built to support GDPR obligations through the DPA, sub-processor transparency, and data subject request handling. We do not currently claim SOC 2, ISO 27001, HIPAA, or PCI certification, and nothing on this page should be read as one. If your procurement process requires a security questionnaire, write to us and we will complete it.

Reporting a vulnerability

If you believe you have found a security issue, email hello@emelum.com with steps to reproduce. We acknowledge reports within three business days and will keep you updated while we investigate. Please do not test against live customer data.

Questions about this document? Email hello@emelum.com.