Skip to main content
ResolveLayerBack to overview ↖

Security · Current beta

A clear boundary around assistance.

ResolveLayer Companion is designed to assist agents inside their existing Zendesk workflow while preserving review, visible evidence and deliberate action.

Last updated 24 August 2026Beta assurance summary · Independent security review pending
ResolveLayer trustPrivacy PolicySecurityTerms of UseGuided demo

Current architecture

Companion is a build-free Manifest V3 browser extension for Chrome and Edge. The core sidebar reads the active Zendesk ticket through the signed-in browser session. Local/BYOK requests are sent directly to the selected provider, so normal core use does not require a ResolveLayer proxy or Zendesk-aware backend.

An approved business account may connect Companion to Control for organisation policy and synchronisation. Managed processing is available only where it has been separately enabled, configured and authorised. These modes are explicit and labelled; provider or processing mode never changes silently.

The ResolveLayer marketing website is separate from Companion. It uses hosted infrastructure to serve pages, retain guided-demo enquiries and record limited first-party website events.

Human control

  • Generated replies remain reviewable before insertion.
  • Only the Zendesk content script can manipulate the composer.
  • Companion does not silently submit an AI-generated reply.
  • Existing composer text is protected unless an agent deliberately chooses an insertion or replacement action.

Provider and knowledge handling

Provider selection and credentials are configured within the extension. Customer content is treated as untrusted private data and crosses the AI boundary only when an agent invokes an AI feature. Knowledge citations shown to agents are validated against enabled text, pinned files or documents retrieved for the current request.

A local provider does not invoke cloud retrieval without explicit hybrid-mode consent.

Storage

Companion currently uses chrome.storage.local for configuration and bounded cross-context records. Credentials remain until disconnect or reset and are excluded from configuration exports. Cached briefs, drafts, knowledge matches, activity metadata and connector evidence use documented limits or retention bounds.

Account Sync is optional. Supported credentials and approved durable local data are encrypted on the device before upload to the Account Vault. ResolveLayer stores only authenticated ciphertext and cannot recover the user-held recovery key or decrypt the vault.

Current assurance position

ResolveLayer does not currently claim ISO 27001, SOC 2 or other independent security certification, and Companion is not positioned as autonomous case resolution. Security documentation will evolve alongside the product and commercial deployment model.

Report a concern

Please send potential security or privacy issues to hello@resolvelayer.com.au with enough detail for Chahine Labs to reproduce and assess the concern. Avoid including unnecessary customer information or live credentials.

ResolveLayer is developed by Chahine Labs.Questions? hello@resolvelayer.com.au