Security

Your conversations are protectedprotected, from the moment you hit send

Every workspace on StaqOn is protected with encryption. Messages are protected before they're stored, automatically — with nothing for your team to configure.

AES-256 at rest Dedicated workspace key Fail-closed
message 01 / 14 Encrypted
encrypting… 0%
01

Your workspace, protected separately

Your workspace has its own dedicated encryption protection, helping keep your stored conversations protected.

02

Protection built in, not bolted on

Security is part of the platform from the start, working quietly in the background as your team communicates.

03

Nothing to configure, ever

Your conversations are protected automatically. No settings to manage. No extra steps for your team.

How it works

From the moment you hit send to the moment someone authorized reads it.

01

You send a message

Typed and sent from your device as usual.

02

Your workspace's key is used

A request goes, over a private connection, to the separate key system holding your workspace's dedicated key.

03

Encrypted before storage

The message is encrypted immediately, before it's ever written to the database. Plaintext is never intentionally stored.

04

Stored as ciphertext

Only scrambled, unreadable data sits in the database.

05

Decrypted for authorized access

When someone with permission views the message, it's decrypted using your workspace's key, then shown to them.

Architecture

How it fits together

Your device Where you type and send
Message server Encrypts, stores ciphertext, decrypts on demand
Separate key server Holds your workspace key. Locked down — no direct message access
Authorized viewer Sees the decrypted message
Data at rest

What's actually in the database

Messages and the key that unlocks them live on separate systems. Nothing readable crosses the boundary.

Message database
id
body
4821
kR9v/2xQ7mLp+Td0aZ1wYhB4nCsE6gJfU8oXdV3q
4822
7HpNc0WqAsZ2LxYt5EjMbG1DvRfK9uOi3TnQeXlS
4823
Qz8FdT1yUvB6WmKh0aPjXcR4sNlE2ZgI7oCtM5rJ
Ciphertext only. Plaintext is never intentionally stored.
Trust
boundary
key request
Separate key server Holds your workspace's dedicated key. It has no direct access to messages, and the message database has no copy of the key. ws_9f2c · locked down
Access & audit

Who can see what

Access follows the permissions you already set in your workspace. Everything else is denied by default.

Your team Sees the conversations their workspace role allows, decrypted at the moment they open them.
Admins Manage members and permissions. Adding or removing access is an action you take, not something we do for you.
The database Holds ciphertext and no key. On its own, it reveals nothing readable.
Key requests Every call to the key system is recorded, so key use can be reviewed after the fact.
In place today
AES-256
Message bodies encrypted at rest
TLS 1.3
Private connections in transit
1 key / workspace
Dedicated, never shared between customers
Fail-closed
No fallback to unprotected storage
Least privilege
Key system isolated from message access
Questions

What security reviewers usually ask

Where is the key kept?

On a separate key system, not alongside your messages. The message database holds no copy of it.

What happens if the database is copied?

A copy contains ciphertext. Without the workspace's key, the message bodies stay unreadable.

Do backups carry the same protection?

Backups are copies of the stored data, so message bodies remain encrypted in them too.

Does my team have to turn anything on?

No. Protection applies to every workspace automatically, with no settings to manage.

What if encryption fails on a message?

The write stops. We don't store the message unprotected as a fallback.

Running a security review?

Send us your questionnaire and we'll walk your team through how StaqOn handles your data.

We'd rather pause than take a risk

If anything prevents a message from being properly protected, we won't store it unprotected. No shortcuts. No fallback to unprotected storage.

Your workspace, in your hands

Your authorized team can continue to access messages through the features you rely on every day. Encryption adds an additional layer of protection to your stored conversations, helping protect your business information from unauthorized access.