Security

Security practices for a multi-model AI workspace.

MultipleChat handles AI workflows, files, conversations, billing events, and account access. This page summarizes the safeguards we describe publicly and how to report security concerns responsibly.

Account and Access

  • Authentication is handled through account login flows rather than shared access links.
  • Users are responsible for keeping account credentials secure and reporting suspicious activity.
  • Team and account areas are separated from public marketing pages and blocked from crawler discovery.

Data Protection

  • NLP GmbH is identified as the data controller in the Privacy Policy.
  • The Privacy Policy describes user rights, data subject requests, retention, subprocessors, and international transfer context.
  • Users should avoid submitting sensitive personal or regulated data unless their intended use is appropriate for the service terms.

Operational Safeguards

  • Public pages, app routes, account routes, payment routes, and API routes are separated in the application structure.
  • Robots directives exclude account, admin, payment, project, chat history, and API paths from crawler discovery.
  • Security and privacy information is linked from trust and legal pages for review before purchase.

Responsible Disclosure

If you believe you have found a security vulnerability, please contact us before public disclosure or testing beyond what is necessary to demonstrate the issue.

[email protected]

Suggested subject: SECURITY DISCLOSURE

Important Scope Note

This page is an overview, not a certification claim. Any enterprise-specific security review, DPA request, or subprocessor question should be directed to the contact channels listed in the Privacy Policy and Impressum.