Workspace separation
Every ticket, asset, article and invitation belongs to an organization. Application queries and access checks are scoped to the current membership.
Security starts with clear access, separated customer data and an honest account of what the product does.
Every ticket, asset, article and invitation belongs to an organization. Application queries and access checks are scoped to the current membership.
Owners and admins manage the workspace; agents handle support; requesters see their own tickets and published articles.
Files are served through authenticated download views with ticket access checks, not through a public media URL.
Stripe and Voredesk webhook endpoints verify signatures and record event IDs to prevent duplicate processing.
Production security also depends on your configured hosting, HTTPS, secrets, backups, email delivery and operational monitoring. Voreflow has not claimed an external audit or certification. Those controls must be verified for the production environment before a public launch.
Ask about the security model →