Saltar al contenido principal

Security overview

PushFeedback is designed to meet enterprise security requirements for data protection, compliance, and transparency.

Configurable security features

FeatureDescription
Role-based access (RBAC)Restricts dashboard access to authorized users with segmented permissions.
Domain restrictionsLimits which domains can embed the feedback widget.
reCAPTCHA v3 protectionOptional invisible bot detection and spam prevention. Learn more.
Rate limitingPer-session and per-IP limits to prevent spam and abuse.
Bearer authenticationEnforces API key authentication for all API requests.
Granular API permissionsScope each API key to specific permissions (project_read, feedback_create).

Security architecture

LayerProtection
NetworkFirewalls, DDoS mitigation, continuous monitoring, and real-time alerts.
Data encryptionEncrypted in transit and at rest. Automated backups for recovery.
Audit logsDetailed logs of security-sensitive operations for accountability.
Account isolationCustomer data is strictly separated between accounts.
Model training opt-outCustomer data is never shared with third-party model training.
GDPR complianceUser data handled in line with European data protection regulations.

AI data handling

PushFeedback uses third-party AI providers to power optional features such as AI-generated feedback reports. The following safeguards are in place:

  • Opt-out of model training: Your feedback data is never used to train or improve AI models.
  • Data sent on demand: Feedback data is only sent to AI providers when an AI feature is actively used.
  • Admin control: Team admins can disable all AI capabilities from Team settings. See Opting out of AI reports for details.

For more information on the AI providers we use, see Our providers.

See the Privacy Policy for details on data handling.