Security at Sonny
Your customers trust you with their data. We take that responsibility seriously. Here is how we keep your data safe.
Your data, your control
We handle your data with care and give you full control over it.
Encrypted everywhere
Your data is encrypted both in transit and at rest using industry-standard protocols.
Security best practices
We follow security best practices throughout the application to protect against common vulnerabilities.
Input validation
All user input is validated server-side. We use strict schemas to prevent injection attacks and malicious data.
XSS prevention
All chat messages and email content are sanitized before rendering to prevent cross-site scripting attacks.
File upload safety
File uploads are validated for type and size (max 25MB). Files are scanned and stored securely in S3.
Webhook verification
All incoming webhooks (Stripe, AWS SES/SNS) are verified using cryptographic signatures before processing.
Multi-tenant isolation
Workspaces are fully isolated at the database level. Every query enforces tenant boundaries to prevent cross-workspace data access.
Regular updates
Dependencies are regularly updated and audited for vulnerabilities. We follow responsible disclosure practices.
Have security questions?
We are happy to answer any questions about our security practices. Reach out to us anytime.
Start free trial