Security

Security & trust

Communities run on trust. Here's how Convoro helps keep yours — and its members — safe.

🔍

AI security review of every add-on

Each marketplace extension is audited from its real source code and gets an unbiased safety verdict before you install — visible right on its listing.

🔒

Hardened by default

CSRF protection, signed webhooks, hashed passwords, scoped API tokens, and a granular permission system are built in.

🧾

Transparent updates

A public changelog and version on every page mean you always know exactly what you are running and what changed.

🛡️

Safe extension model

Extensions are reviewed, version-pinnable, and pulled from public source you can inspect — no opaque binary blobs.

Responsible disclosure

Found a vulnerability? Please report it privately to security@convoro.co before disclosing publicly. We investigate every report and will credit you once a fix ships.