Security, stated plainly
Defensible claims about how customer data is isolated, checked, and audited. No certifications are claimed here — when independent audits happen, they will be published.
Tenant isolation
Every customer resource is scoped server-side by customer. Cross-tenant reads resolve as not-found at the API, repository, and database layers.
Server-side entitlement
Sensitive contact data, exports, CRM pushes, and outreach enrollment all re-check entitlement and payment on the server. The browser never decides access.
Credential handling
Passwords are salted scrypt hashes; session and API tokens are stored as hashes only. Browser sessions live in HttpOnly, Secure-in-production cookies — never localStorage.
API-key separation
Programmatic keys are hashed, scoped, revocable, and shown once. Workspace sign-in never requires pasting a key.
Auditability
Privileged operations keep immutable history: commercial events, QA verdicts, deliveries, outreach runs, and operator actions.
Suppression enforcement
Bounces, complaints, and unsubscribes suppress sending durably, including a global list. Suppressed recipients cannot be forced through outreach.
Evidence tracking
Field-level provenance records which source observed each value and when — the same trail customers see.
Responsible limits
- Anonymous demo data is synthetic — nothing real can leak from it.
- HubSpot delivery is push-only; your CRM changes are never synced back.
- AI drafts require explicit human approval before anything sends.