Security

Customer accounts and their data stay separate.

COMS processes conversations, leads and bookings. Access is limited by role, traffic is encrypted and integrations are connected to the correct customer account.

Separate customer accounts

Each customer can access only their own data, Chatbot and settings.

Role-based access

Provider owners, customer admins and operators have separate permissions.

Private customer data

Uploaded files, conversations and enquiries are kept within the customer's account.

Production checks

Schema, tenant data, CSP and asset checks support release readiness.

Current status

Clear claims, no inflated certification badges.

COMS uses account isolation, access control and documented security checks. COMS is not ISO 27001 certified.

How COMS is secured

Security is handled as product architecture, not as an afterthought.

Account isolation

Every widget, conversation, lead, contact, booking, file and delivery channel is tied to a customer account. The goal is to prevent customer data from mixing across UI and database boundaries.

  • Account-scoped database structures
  • RLS policies
  • Allowed widget origins
  • Cross-account production checks

Roles and permissions

The portal separates COMS owner management, customer admin access and operational users. This lets leadership manage settings while sales or marketing users work with narrower daily permissions.

  • Provider owner manages customers
  • Customer admin manages one account
  • Operators use messages, contacts and tasks

Traffic and storage

Service traffic uses HTTPS/TLS. Customer uploads and operational data are designed for private, account-scoped use.

  • HTTPS/TLS
  • Private account-scoped file paths
  • CSP and origin restrictions
  • Production checks for storage paths

Integration management

Leads can be delivered to email, webhook, WhatsApp, Telegram or other agreed channels. Each delivery channel is tied to a customer account so deliveries do not mix across customers.

  • Customer-scoped delivery channels
  • Limited credentials and keys
  • Delivery event logging
  • Ability to disable or rotate channels

Operations and release checks

COMS includes checks for schema readiness, tenant data, portal assets, CSP settings and smoke testing. Checks support releases, but do not replace continuous monitoring.

  • Schema readiness
  • Tenant data verification
  • Portal asset checks
  • Production smoke checks

Separate legal pages

Privacy and terms stay separate from the security overview.

This page explains how COMS protects accounts and customer data. Privacy details and service terms are available on their own pages.

Security contact

Ask about requirements or report a finding.

info@coms.fi