Tenant-isolated data
Every query is scoped to a tenant in the data layer rather than relying on each query to remember. One customer's agents cannot reach another's tickets, knowledge or reports.
Security and data protection
Support tickets are among the most sensitive data a business holds: names, contact details, order histories, complaints, sometimes payment references. This page describes the controls that exist in the product today. Where something does not exist, it says so.
The two questions every support buyer asks first: can another customer see our data, and can our own staff see more than they should.
Every query is scoped to a tenant in the data layer rather than relying on each query to remember. One customer's agents cannot reach another's tickets, knowledge or reports.
Privileged routes check a named permission, not merely that somebody is logged in. Roles and team access are configurable per workspace.
Agent passwords are hashed with Argon2, the current password-hashing standard, rather than a general-purpose hash.
A failed login costs the same time whether the address exists or not. Equalising that closes a leak where identical error text still reveals real accounts through response timing.
Public and authenticated endpoints are rate limited, including the intake routes that anyone on the internet can reach.
API keys you supply for an AI provider are encrypted at rest rather than stored as readable text.
This is the part most support tools are vague about, so here it is precisely.
Email addresses, payment card numbers, phone numbers, provider credentials, and Aadhaar, PAN and GSTIN numbers are replaced before a request reaches an external model, then restored in the finished draft. Names and free-text details are not removed.
Answers are drafted from articles in your knowledge base, and only the articles actually cited are attached to the draft. Whether a draft counts as grounded is decided by the server, not reported by the model.
There is no action in the automation system that sends a customer-facing AI reply on its own. Automation handles tagging, priority, routing, assignment and status; a human decides what is said.
A cited article past its review date is marked on the draft, so an agent can see the answer rests on something nobody has checked recently.
A cached draft contains the restored personal values, so it is purged on erasure along with everything else. An erasure that skipped the cache would quietly leave the data behind.
When nothing in your knowledge covers a request it goes to an agent rather than getting a guess. That is the designed outcome, not a failure.
The mechanism is described in more detail in how grounded AI works.
India's Digital Personal Data Protection Act, 2023 gives people rights over their data, and those rights are worth nothing if the software cannot act on them. Rezolo Desk has the operations built in rather than leaving them as a manual database job.
Returns a customer's record, their tickets and the messages they sent. Permission-gated, and the request itself is written to the audit log.
Anonymises the customer record, erases the message bodies they wrote, and purges cached AI output for them.
Retention periods are set per workspace rather than fixed by us, because how long a support record should live is your policy decision.
Your support data is deleted when you leave. It is your data while you are a customer and it does not become ours afterwards.
Every mutation writes a tenant-scoped audit event. Personal detail is redacted inside the log entries themselves, so the audit trail is not a second copy of the data it describes.
What file types and sizes may be attached is a workspace policy, enforced server-side rather than only in the browser.
A security page that only lists strengths tells you nothing, because every vendor's page looks the same. These are the honest gaps, stated here rather than discovered by your legal team three weeks into an evaluation.
Rezolo holds no third-party security certification and has not commissioned an external penetration test. Everything on this page is engineering we can demonstrate, not an audit somebody else has signed.
The product is designed around the DPDP Act, 2023 and implements the operations it requires. That is a design commitment, not a certified compliance status, and nobody can issue you the latter today.
We do not currently offer a choice of storage region. If residency is a hard requirement, raise it during onboarding so we can be straight about whether we fit.
Agent sign-in is email and password today. If your security policy requires SSO or enforced MFA, tell us early rather than late.
It removes structured identifiers, not every trace of a person. Names and details written in free text reach the model, and national identifiers from outside India, such as SSNs, Emirates IDs or IBANs, are not yet recognised.
Rezolo Desk is onboarding a selected group of early teams. You should weigh that alongside everything above rather than treating this as a mature enterprise platform.
Something here not covered, or need detail for a security review? Write to hello@rezolo.in and we will answer specifically. Our website privacy practices are in the privacy and DPDP notice.
Talk to us
Reach out at hello@rezolo.in. We will understand your requirements first, then guide you on the commercials.