WPISTIC
Security

How we protect your data

WPistic products handle real customer data — chat conversations, CRM records, booking details. Here's a plain-language look at how we approach security across the dashboard, the products, and the infrastructure behind them.

WordPressistic LLC · Security reports: security@wpistic.com

Our approach

Concrete practices, not vague promises

Encryption in transit and at rest

All traffic between your site, the WPistic dashboard, and our APIs is encrypted over TLS. Customer data is encrypted at rest in our database and backup storage.

Access controls & role-based permissions

Dashboard access is scoped per account, with role-based permissions for team members on Agency and Enterprise plans. Internal access to production systems is limited to the engineers who need it, and logged.

Infrastructure & hosting

WPistic runs on reputable cloud infrastructure with isolated environments per service, automated backups, and network-level access restrictions between production and everything else.

Patching & update cadence

Dependencies and platform components are monitored for known vulnerabilities and patched on a regular cadence, with critical security fixes shipped outside the normal release schedule.

Compliance posture

We're an early-stage company and don't hold formal certifications like SOC 2 or ISO 27001 today. Formal compliance work is on our roadmap as we grow — we'd rather say that plainly than claim something we haven't earned.

Report a vulnerability

Found a security issue? Tell us directly.

We take security reports seriously and welcome responsible disclosure. Email us with details — what you found, how to reproduce it, and its potential impact — and we'll respond within 1 business day.

security@wpistic.com
What to include

Affected product or endpoint, steps to reproduce, and any proof-of-concept details that help us confirm the issue quickly.

What we ask in return

Give us a reasonable window to investigate and patch before any public disclosure. Please avoid accessing or modifying data that isn't yours.