Skip to main content

How Templ keeps users and teams safe

Chat cannot sign or send transactions. Wallet sign-in binds the approved site and . Each user reads their own . Each team action checks current access. Never share a private key or recovery phrase.

Protect users​

Sign in through the sign-in card. Templ refuses team messages that ask users to sign, approve or send. Templ refuses recognized recovery phrases and private keys before storage. Ambiguous hex values and Solana signatures stay visible to your team and the user. Templ hides them from bots, webhooks, AI and exports unless shared as a typed transaction. A can redact them.

Wallet proof proves address control at that time. It does not prove a person's identity. Spot fake support explains what users should check.

Check team access​

Managers grant explicit roles. Billing, assignments, token ownership and display names grant no case permission. Every private read, reply, export, search result, attachment and event checks current access. Removing support access ends access to retained history and open connections. Private cases never become public. Messages are not end-to-end encrypted. A saved export or screenshot can leave Templ's access checks.

Stop team messages stops replies, initiation and reopening, including managers and . Only the user can ask again and lift the stop.

Check AI providers​

Your agent's operator chooses its model provider and which case data it receives. That provider is the company that runs its model. Tell users which provider receives their messages and apply your agreed retention rules. Keep , secrets and unrelated cases out of model inputs. Templ's own support AI uses OpenAI when enabled. Templ-managed customer agents use Anthropic when that service is ordered and enabled.

Limit Templ access​

A signed gives Templ people no case access by itself. The form must allow Templ staff access. Your manager grants each person a team role under the signed order form. The active form, current role and approved Templ account are required on every access check. Removing any requirement ends access, including open connections. Operators, billing and order forms give no case access.

Review data and providers​

Case data explains retention and exports. De-identified copies explains the separate improvement copy. Read Trust and Privacy for providers and data terms.

Report a problem​

For a security report, use security@usetempl.com. Do not include a private key or recovery phrase.

Details for developers​

The app uses SIWE or SIWS wallet sessions. Email verifies an alert address and never signs in or merges accounts. Challenges bind domain, URI, chain, nonce and expiry. Widget challenges also bind the intended workspace resource. A widget session has only the member permission role and gains no app or team authority. sessions share the exact origin and workspace scope. Contract-wallet signatures fail closed without their supported verification. Keep replay and revocation checks. See the widget reference.