META Z logoMETA Z VN
Back to website
SECURITY BY CONTROL · BẢO MẬT THEO PHẠM VI

Security Overview

Security begins with the right account, the right role and a traceable action.

Updated: 15 July 2026Security contact: [email protected]
PrinciplesActivation gatePilot statusTikTok MessagingPrivacyData deletion

Security principles

Business-controlled authorization

Connected advertising and messaging accounts must be authorized by an eligible business representative. Access can be revoked from the service or the connected platform.

Channel-scoped permissions

OmniDesk is designed so an employee can only read and reply on channel accounts explicitly assigned to that employee. Owners and administrators control assignments, remove access when it is no longer required and perform periodic access reviews.

Organization separation

Customer records, conversations and channel memberships are scoped to their organization. Requests are checked against organization, user and channel context before protected records are returned or changed.

Credential protection

Platform secrets and access tokens are not embedded in public pages or client-side code. Production credentials are restricted to authorized server-side processes. Revocation and rotation are required when compromise is suspected or an authorization is withdrawn.

Secure operations

Security-relevant events, administrative actions and outbound replies are designed to be attributable to the responsible account. Operational review, dependency maintenance, backup recovery and incident handling form part of the production-readiness process.

Data minimization

Only information needed for an authorized service purpose should be collected. Access, retention and deletion are limited according to customer instructions, platform requirements and law.

Production activation gate

A live third-party messaging connection is not enabled solely because a user can see a connect button. The following controls must be validated for the relevant integration before production credentials and real customer data are used:

Transport and webhook

HTTPS-only endpoints, provider challenge/verification handling, event authenticity checks where provided, idempotent processing and replay protection.

Secrets and tokens

Server-side secret storage, restricted process access, encrypted protection appropriate to the hosting environment, expiry handling, revocation and rotation.

Authorization boundary

Organization, user and channel checks on every protected operation; least-privilege roles; administrator-controlled assignment and prompt removal.

Logging and response

Audit records for authorization, assignment, administrative changes and outbound replies; alerting, incident triage, containment and documented escalation.

Data lifecycle

Documented retention, deletion and backup-expiry schedules; tested disconnect/revoke behavior; verified deletion request and completion records.

Release assurance

Dependency review, vulnerability remediation, environment separation, backup/restore testing and a reviewer-safe demonstration using non-sensitive test data.

The detailed TikTok use case, requested permissions and data flow are published in the TikTok Business Messaging Integration Disclosure.

Pilot and integration status

OmniDesk and related automation integrations are in staged development. Connections to TikTok, Meta, Google, Shopee, TikTok Shop or another provider will not be activated until the provider grants the required API access, applicable review requirements are completed and an eligible business account owner authorizes the connection.

Security controls are validated progressively before production use. This page does not claim a third-party certification and should not be read as a guarantee that every risk can be eliminated.

Reporting a concern

Email [email protected] with a clear description, affected URL or feature and safe reproduction steps. Do not include passwords, private keys, access tokens or unrelated personal data.

Tổng quan bảo mật bằng tiếng Việt

Ủy quyền do doanh nghiệp kiểm soát

Tài khoản quảng cáo hoặc nhắn tin chỉ được kết nối bởi đại diện doanh nghiệp đủ thẩm quyền và có thể bị thu hồi quyền từ dịch vụ hoặc nền tảng kết nối.

Phân quyền theo từng kênh

OmniDesk được thiết kế để nhân viên chỉ đọc và trả lời trên đúng tài khoản kênh đã được gán. Chủ sở hữu và quản trị viên kiểm soát việc phân công và cần rà soát quyền định kỳ.

Tách biệt tổ chức

Hồ sơ khách hàng, hội thoại và thành viên kênh được giới hạn trong tổ chức tương ứng. Yêu cầu truy cập được kiểm tra theo tổ chức, người dùng và kênh trước khi trả về hoặc thay đổi dữ liệu bảo vệ.

Bảo vệ thông tin xác thực

Secret và access token của nền tảng không được đặt trong trang công khai hoặc mã chạy phía trình duyệt. Thông tin xác thực chính thức phải được giới hạn cho tiến trình máy chủ được phép và được thay đổi khi nghi ngờ bị lộ.

Điều kiện kích hoạt chính thức

Trước khi sử dụng credential thật và dữ liệu khách hàng thật, tích hợp phải vượt qua kiểm tra HTTPS/webhook, bảo vệ token, phân quyền theo tổ chức và kênh, nhật ký truy vết, xử lý sự cố, lưu giữ/xóa dữ liệu và kiểm tra sao lưu–khôi phục.

Trạng thái thử nghiệm

OmniDesk và các tích hợp automation liên quan đang được phát triển theo từng giai đoạn. Kết nối TikTok, Meta, Google, Shopee, TikTok Shop hoặc nhà cung cấp khác sẽ chưa được kích hoạt cho đến khi nền tảng cấp quyền API cần thiết, hoàn tất yêu cầu xét duyệt áp dụng và chủ tài khoản doanh nghiệp đủ điều kiện thực hiện ủy quyền.

Báo cáo vấn đề

Gửi mô tả rõ ràng tới [email protected]. Không gửi mật khẩu, private key, access token hoặc dữ liệu cá nhân không liên quan.

© 2026 META Z VN
TikTok MessagingPrivacyTermsData deletion