Security, stated plainly

Defensible claims about how customer data is isolated, checked, and audited. No certifications are claimed here — when independent audits happen, they will be published.

Tenant isolation

Every customer resource is scoped server-side by customer. Cross-tenant reads resolve as not-found at the API, repository, and database layers.

Server-side entitlement

Sensitive contact data, exports, CRM pushes, and outreach enrollment all re-check entitlement and payment on the server. The browser never decides access.

Credential handling

Passwords are salted scrypt hashes; session and API tokens are stored as hashes only. Browser sessions live in HttpOnly, Secure-in-production cookies — never localStorage.

API-key separation

Programmatic keys are hashed, scoped, revocable, and shown once. Workspace sign-in never requires pasting a key.

Auditability

Privileged operations keep immutable history: commercial events, QA verdicts, deliveries, outreach runs, and operator actions.

Suppression enforcement

Bounces, complaints, and unsubscribes suppress sending durably, including a global list. Suppressed recipients cannot be forced through outreach.

Evidence tracking

Field-level provenance records which source observed each value and when — the same trail customers see.

Responsible limits

  • Anonymous demo data is synthetic — nothing real can leak from it.
  • HubSpot delivery is push-only; your CRM changes are never synced back.
  • AI drafts require explicit human approval before anything sends.