Security and privacy

Know what is protected—and what remains your responsibility.

This is a customer-facing explanation, not an internal topology or deployment guide.

Version 2026.08Owner: BeKordLast reviewed: August 7, 2026Review after material security changes

Service safeguards

TLS protects supported browser traffic in transit. Passwords are stored as hashes, email verification protects enrollment, optional authenticator-based 2FA strengthens accounts, provider admin actions require short-lived re-authentication, and operational backups are encrypted and access-restricted.

Important boundary

BeKord does not claim end-to-end encryption. The provider operates the application and service infrastructure. Authorized workspace access is controlled by membership, roles, permissions, and scoped application queries; provider infrastructure administrators retain technical power needed to operate and secure the service.

Your responsibilities

  • Use a unique strong password and enable 2FA.
  • Protect email, recovery information, invitations, and webhook URLs.
  • Do not paste credentials, tokens, or unnecessary private content into support forms.
  • Review workspace permissions and remove access that is no longer needed.
  • Report suspected compromise promptly.

Data and retention

Account, workspace, communication, operational, support, and security data are processed only as described in the Privacy Notice. Support and beta feedback follow the published retention rules. Aggregate onboarding measurements do not read message bodies, credentials, or browsing history.

Report safely

Use Support and choose Security vulnerability, Privacy request, Abuse report, or the category that fits. Do not test other customers, disrupt the service, or upload prohibited material. For immediate danger, contact local emergency services.