01
Encrypted transport
Dashboard and API traffic are designed to run over HTTPS. Destination calls use HTTPS URLs.
Reference
Security
A factual overview of the protections currently represented in Truehook. We do not claim certifications or guarantees that have not been independently verified.
Dashboard and API traffic are designed to run over HTTPS. Destination calls use HTTPS URLs.
Per-endpoint secrets support request authentication and timestamp-based replay protection.
API keys are stored as hashes, can be scoped, monitored, and revoked from the workspace.
Retries, attempt history, and dead-letter controls make delivery failure visible and actionable.
If you believe you found a security issue, do not include secrets or customer payloads in your first message. Contact the team with a concise reproduction and impact assessment.
security@truehook.in