Security

What you can show IT today

2FA, four roles, a JSON export, account delete, TLS, and an audit log that records invite, export, ban, and delete. Operators use Google, Microsoft, a magic link, and 2FA. An invite is still required to join a workspace. Not SAML. Login history is still a placeholder.

Sign-in

Google, Microsoft, a magic link, and 2FA

Operators sign in with Google, Microsoft, a magic link emailed to their work address, or email plus a password. Authenticator 2FA is available at sign-in (Authy or Google Authenticator). That is the SSO we ship. Not SAML. A Google or Microsoft account does not join a workspace by itself — someone has to invite you, or you create your own. Owners can optionally list allowed email domains in Settings → Security. See pricing.

Four roles

RoleWhat they can do
OwnerBilling, workspace, widget, team, articles, export, delete.
AdminWidget, team, articles, inbox, workspace export. Not billing.
AgentInbox. Reply, assign, resolve, notes, contact export.
ViewerRead-only if you see it in the picker.

There are no custom roles and no team inboxes. Invite from Settings. Do not share one login — assignment and typing need a real seat.

GDPR export

  1. 1. Open Settings → Security. Privacy sits on that tab. Same path in the Cove Inbox app.
  2. 2. One contact. Enter an email or contact id. Any member who can export a contact gets JSON: profile, conversations, messages the desk can already open.
  3. 3. Whole workspace. Owners and admins only. Every person and thread in the tenant, capped if the desk is very large.

Help: GDPR export. Legal text: Privacy.

Account delete

Settings → Security → Delete account. Type DELETE. We remove the auth user (email, password, Google/Microsoft sign-in, 2FA) and take you off every workspace. If you are the only member, that workspace and its inbox, people, help, and widget data go with it. Paid subscriptions on those workspaces are cancelled when we can. Teammates’ accounts stay. Daily backups may lag by a day. The last owner of a workspace that still has teammates must promote another owner first.

Audit scope

The audit log records invite, export, ban, unban, and account delete. Owners and admins can read it. That is the list.

Login history is a placeholder. The plate says sign-in devices will show once we record them. Fake history was removed. We do not currently store a device list.

TLS, origin lock, backups

TLS in transit. The public widget key is locked to origins you list. Daily snapshots. Card data stays with Dodo Payments. Subprocessors are on Privacy: Supabase, Cloudflare, Dodo, Resend. We do not currently offer a customer-selectable EU-only region.

What we do not claim

  • SAML — operators use Google, Microsoft, a magic link, and 2FA. Not SAML.
  • HIPAA
  • SOC 2 — ask help@coveinbox.co if you need a current report rather than assuming we have one
  • Operator web push (VAPID is not live)
  • A customer status product — /status is platform totals

FAQ

Frequently asked questions

Sign-in, roles, export, delete, and what the audit log actually records.

No. Not SAML, not HIPAA, not SOC 2. Ask help@coveinbox.co if you need a current security report rather than assuming a badge. Sign-in is Google, Microsoft, magic-link, and 2FA. See pricing.

The plate is a placeholder. We do not record devices yet. Fake history was removed.

Invite, export, ban, unban, and account delete. That is the list.

Blog

How the desk runs

Show this page to IT. Then start the trial.

Google, Microsoft, magic-link, and 2FA. Invite still required to join a workspace. Fourteen-day trial.