Woes

Trust

Trust in Woes starts with API evidence and tenant isolation.

Woes is designed around workspace boundaries, API evidence, credential separation, and human control.

Last updated: July 4, 2026

Workspace boundaries

Woes stores support conversations, issues, API sources, credentials, and settings as workspace-owned records. Every workspace-owned query and route is scoped to the active workspace boundary and enforced at the database with row-level security. Public widget access uses a workspace public key plus route-level controls, and never grants general table access.

API credentials

API credentials are stored separately from source documentation. They are encrypted at rest, used only for supported testing workflows, redacted before model calls, and never returned in plaintext to customers or AI responses. Bring-your-own-AI provider keys are stored encrypted and used only to route that workspace’s AI requests.

Encryption and data protection

  • Data is encrypted in transit with TLS and at rest.
  • Secrets, API credentials, and provider keys are encrypted and kept out of source content.
  • Sensitive values are redacted before content is sent to AI providers.

Grounded AI behavior

  • Answers rely on retrieved workspace API context.
  • Endpoint, auth, schema, request, and response claims are supported by evidence.
  • The agent clarifies or hands off when available context is not enough.
  • Operators can inspect context, take over conversations, and improve future support quality.
  • Your workspace content is not used to train Woes models.

Infrastructure and sub-processors

Woes runs on Vercel for application hosting and Supabase for the database, authentication, and file storage. Billing is handled by Stripe, transactional and support email by Resend, and error monitoring by Sentry. AI processing is routed through vetted providers (Anthropic, OpenAI, and Google). The full list, with the purpose of each provider, is in our Privacy Policy.

Access controls and auditing

Access to workspace data is role-scoped, and operator and customer information boundaries are preserved across the inbox. Administrative and cross-tenant support actions are logged to an audit trail, and any operator impersonation is recorded.

Responsible disclosure

If you believe you have found a security vulnerability, please report it to support@woes.dev so we can investigate and respond. Please give us a reasonable window to remediate before any public disclosure.

Related trust controls

Read how Woes handles grounded AI support, authenticated API testing, and the broader API support workflow. See also our Privacy Policy and Terms of Service.

Questions

For security, privacy, or trust questions, contact support@woes.dev.