Security model Current product controls

Trust needs verifiable boundaries.

MessageHop uses organization isolation, scoped credentials, server-side authorization, separate trust zones, immutable evidence, and fail-closed product behavior. This page describes implemented product controls; it does not claim a certification or universal guarantee.

Tenant isolation

Organization is the boundary

Active membership and verified parent ownership are required for customer resources. A browser-supplied organization or role is never authoritative.

Credentials

Secrets stay on trusted servers

Customer server secrets are shown once and stored as verification material. Provider credentials use managed secret storage.

Authorization

Permission includes context

Protected operations evaluate identity, action, resource, scope, active state, recent sign-in, MFA, and command context as required.

Trust zones

Customer, Staff, and Admin stay separate

Routine support does not imply platform administration. Privileged sessions are permission-gated, TOTP-backed, and time-bounded.

Integrity

Message and billing evidence is durable

Idempotent acceptance, bounded dispatch, immutable ledger events, price snapshots, and reconciliation protect against duplicates and silent rewrites.

Privileged commands

Sensitive changes leave evidence

High-impact workflows require reason, audit, recent authentication, MFA, and a different reviewer where two-person approval applies.

Support privacy

Visibility is explicit

Customer replies and internal notes are separate backend states. Attachments use ticket-scoped authorization and safe metadata.

Web security

Public and console surfaces are isolated

Hosting denies framing, restricts browser capabilities, prevents console indexing, and keeps public REST routes explicitly bounded.

Reporting

Tell us what you found

Email security@msghop.com with safe reproduction steps and impact. Never include credentials, customer message content, or unnecessary personal data.