//Legal
Security
Last updated: 29 July 2026. This page is maintained by Emelum to answer common security and privacy questions about ConvoSell. It describes the controls we operate today — it is not a certification or an independent audit.
Controls we operate
Encryption in transit
All traffic to the site and the platform is served over TLS. Integration credentials are transmitted over encrypted channels only.
Access control
Platform data is protected by row-level security policies. Administrative access follows least privilege and is limited to the personnel who operate the service.
Project-scoped isolation
Each customer workspace is scoped so that conversations, carts, and CRM records are readable only within that workspace.
Human approval on escalation
Actions that carry commercial or legal weight — refunds, exceptions, contested returns — are routed to a human before they are committed.
Audit trail of agent actions
Every automated action the agent takes is recorded with its trigger, the data it read, and the system it wrote to, so the sequence can be reconstructed.
Credential handling
Integration tokens for CRM and commerce platforms are stored as secrets, never in application code, and are revocable by the customer at any time.
Shared responsibility
Emelum is responsible for operating and securing the ConvoSell platform and the infrastructure it runs on. Customers are responsible for who they grant workspace access to, which third-party systems they connect, the accuracy of the data they send, and the policies their agents are configured to follow. End customers are responsible for the content they choose to share in a conversation.
Data handling
Conversation and order data is processed to deliver the service and is not used to train general-purpose models. Retention, sub-processors, and deletion commitments are set out in the Data Processing Addendum and the Privacy Policy.
Compliance posture
ConvoSell is built to support GDPR obligations through the DPA, sub-processor transparency, and data subject request handling. We do not currently claim SOC 2, ISO 27001, HIPAA, or PCI certification, and nothing on this page should be read as one. If your procurement process requires a security questionnaire, write to us and we will complete it.
Reporting a vulnerability
If you believe you have found a security issue, email hello@emelum.com with steps to reproduce. We acknowledge reports within three business days and will keep you updated while we investigate. Please do not test against live customer data.
Questions about this document? Email hello@emelum.com.