How we protect your data
WPistic products handle real customer data — chat conversations, CRM records, booking details. Here's a plain-language look at how we approach security across the dashboard, the products, and the infrastructure behind them.
WordPressistic LLC · Security reports: security@wpistic.com
Concrete practices, not vague promises
Encryption in transit and at rest
All traffic between your site, the WPistic dashboard, and our APIs is encrypted over TLS. Customer data is encrypted at rest in our database and backup storage.
Access controls & role-based permissions
Dashboard access is scoped per account, with role-based permissions for team members on Agency and Enterprise plans. Internal access to production systems is limited to the engineers who need it, and logged.
Infrastructure & hosting
WPistic runs on reputable cloud infrastructure with isolated environments per service, automated backups, and network-level access restrictions between production and everything else.
Patching & update cadence
Dependencies and platform components are monitored for known vulnerabilities and patched on a regular cadence, with critical security fixes shipped outside the normal release schedule.
Compliance posture
We're an early-stage company and don't hold formal certifications like SOC 2 or ISO 27001 today. Formal compliance work is on our roadmap as we grow — we'd rather say that plainly than claim something we haven't earned.
Found a security issue? Tell us directly.
We take security reports seriously and welcome responsible disclosure. Email us with details — what you found, how to reproduce it, and its potential impact — and we'll respond within 1 business day.
security@wpistic.comAffected product or endpoint, steps to reproduce, and any proof-of-concept details that help us confirm the issue quickly.
Give us a reasonable window to investigate and patch before any public disclosure. Please avoid accessing or modifying data that isn't yours.