Security Best Practices
Last updated: November 29, 2025
Protect your SimpleChat account and customer data with these security recommendations.
Create secure passwords:
- Minimum 12 characters
- Mix of upper and lowercase
- Include numbers and symbols
- Avoid dictionary words
- Don't reuse passwords
Good: Tr0ub4dor&3#Horse
Bad: password123
Enable 2FA for extra protection:
- Go to Profile > Security
- Enable 2FA
- Use authenticator app (Google Authenticator, Authy)
- Store backup codes safely
Periodically review:
- Active sessions
- Connected devices
- Recent login activity
- API tokens (if any)
Protect customer information:
- Only collect necessary data
- Use GDPR-compliant settings
- Honor deletion requests
- Export and store securely
If you have team members:
- Use individual accounts
- Don't share login credentials
- Remove access when needed
- Review permissions regularly
- Use HTTPS always
- Keep browser updated
- Use reputable extensions only
- Clear sessions on shared computers
Consider using:
- 1Password
- LastPass
- Bitwarden
- Browser built-in managers
SimpleChat will NEVER ask for:
- Your password via email
- Credit card details via email
- Account verification links (suspicious)
If suspicious:
- Don't click links
- Check sender address carefully
- Contact support directly
- Keep email verified
- Update if email changes
- Use a secure email provider
If using API tokens:
- Keep tokens secret
- Rotate regularly
- Use minimum permissions
- Revoke unused tokens
If using webhooks:
- Verify signatures
- Use HTTPS endpoints
- Validate payloads
- Log for auditing
- Use screen locks
- Enable device encryption
- Keep OS updated
- Install security updates
When using public computers:
- Always log out
- Don't save passwords
- Use private browsing
- Clear history after
Immediate Steps:
- Change password immediately
- Enable/reset 2FA
- Review recent activity
- Check billing for unauthorized charges
- Contact support
Report if you notice:
- Unknown logins
- Changed settings
- Messages you didn't send
- Billing changes
- SSL/TLS encryption
- Regular security audits
- DDoS protection
- Secure data centers
- Encrypted at rest
- Encrypted in transit
- Regular backups
- Access logging
- GDPR compliant
- SOC 2 principles
- Regular penetration testing
- Bug bounty program
- Strong, unique password set
- 2FA enabled
- Email verified
- Recovery options set
- Regular security reviews
- Unused sessions cleared
- Team access reviewed (if applicable)
Contact us immediately for:
- Suspected breaches
- Unusual activity
- Security questions
- Vulnerability reports
Email: security@simplechat.bot