Current architecture
Companion is a build-free Manifest V3 browser extension for Chrome and Edge. The core sidebar reads the active Zendesk ticket through the signed-in browser session. Local/BYOK requests are sent directly to the selected provider, so normal core use does not require a ResolveLayer proxy or Zendesk-aware backend.
An approved business account may connect Companion to Control for organisation policy and synchronisation. Managed processing is available only where it has been separately enabled, configured and authorised. These modes are explicit and labelled; provider or processing mode never changes silently.
The ResolveLayer marketing website is separate from Companion. It uses hosted infrastructure to serve pages, retain guided-demo enquiries and record limited first-party website events.
Human control
- Generated replies remain reviewable before insertion.
- Only the Zendesk content script can manipulate the composer.
- Companion does not silently submit an AI-generated reply.
- Existing composer text is protected unless an agent deliberately chooses an insertion or replacement action.
Provider and knowledge handling
Provider selection and credentials are configured within the extension. Customer content is treated as untrusted private data and crosses the AI boundary only when an agent invokes an AI feature. Knowledge citations shown to agents are validated against enabled text, pinned files or documents retrieved for the current request.
A local provider does not invoke cloud retrieval without explicit hybrid-mode consent.
Storage
Companion currently uses chrome.storage.local for configuration and bounded cross-context records. Credentials remain until disconnect or reset and are excluded from configuration exports. Cached briefs, drafts, knowledge matches, activity metadata and connector evidence use documented limits or retention bounds.
Account Sync is optional. Supported credentials and approved durable local data are encrypted on the device before upload to the Account Vault. ResolveLayer stores only authenticated ciphertext and cannot recover the user-held recovery key or decrypt the vault.
Current assurance position
ResolveLayer does not currently claim ISO 27001, SOC 2 or other independent security certification, and Companion is not positioned as autonomous case resolution. Security documentation will evolve alongside the product and commercial deployment model.
Report a concern
Please send potential security or privacy issues to hello@resolvelayer.com.au with enough detail for Chahine Labs to reproduce and assess the concern. Avoid including unnecessary customer information or live credentials.