Security layers
Dolphy does not leave security to one model instruction. Data queries, channel intake, tool calls and administrative access are validated at their own technical boundaries.
Tenant isolation
Business data is scoped by tenant and agent identities. Even when knowledge retrieval uses a server-privileged client, the tenant filter is applied inside the data query. A caller passing the wrong parameter should not place another business's content into a shared candidate pool.
Widget and channels
The web widget's public site key is validated together with request origin. A site outside the allow-list cannot access configuration merely by copying the key. WhatsApp, Instagram and Messenger webhooks validate the platform signature, event type and connected asset.
Action security
Webhook actions are bounded by an HTTPS target, permitted method, input schema and size limit. Private or local network destinations remain blocked after DNS resolution and redirects. Requests can use an HMAC signature and timestamp, while write operations can require customer confirmation. See Tools and actions for details.
Data minimisation and KVKK
Your organisation must define what data is processed, for which purpose, on what legal basis, for how long, and how people can exercise their rights. Collect only fields required for the use case; do not make health, identity or payment data a default form field.
Access roles, deletion and retention should be configured together with the real operating process. Technical controls do not replace privacy notices or legal obligations. Review your specific context with legal and information-security professionals.
The same principle applies to site traffic measurement: total visits are kept with an anonymous counter, with no per-person record. See the visitor analytics page for details.