Your pipeline is your business. We treat it that way.
Security isn't a page we wrote for compliance — it's the set of decisions behind every workspace, every session and every export.
The guarantees that ship with every plan.
Org-scoped isolation
Every workspace is fully isolated. Users, leads, signals, sequences and analytics are scoped to your organisation — there is no path to another tenant's data.
Encryption in transit & at rest
Traffic is encrypted in transit, and stored integration secrets are sealed with field-level Fernet encryption (AES-128-CBC + HMAC-SHA256). The same key powers an encrypted workspace export that is useless off-platform.
Hashed credentials & lockout
Passwords are stored only as salted hashes — never in plain text. Sign-in is guarded by per-identity rate limiting and a progressive account lockout, and every attempt is written to an auth-event ledger.
Hardened sessions
Session cookies are HttpOnly, SameSite=Lax and Secure under TLS. The session rotates on login to prevent fixation, and sign-out-everywhere revokes every other cookie immediately.
Hardened request handling
Every response carries a strict Content-Security-Policy with a per-request nonce, X-Frame-Options: DENY, nosniff, a referrer and permissions policy, and HSTS when served over TLS.
No training on your data
Your leads and signals are never used to train models for other customers. Your per-workspace ranker learns only from your own outcomes.
Audit trail & accountability
Logins, lockouts, revocations and workspace actions are recorded with IP, outcome and detail — so there is always an attributable history of who did what, and when.
Data portability
Export your leads and analytics as CSV at any time, or download a sealed, encrypted workspace archive. Leave whenever you like — your data leaves with you.
What happens on every request.
You authenticate
Your password is verified against a salted hash, and a signed session is issued. Failed attempts are rate-limited, and no error reveals whether the account exists.
Your workspace is scoped
Every query is filtered to your organisation. Records from other tenants are not merely hidden — they are not part of the data returned to your request.
State changes are verified
Forms and API calls carry a CSRF token. Requests without a valid token are rejected, so a malicious page cannot act as you — and every post-login redirect is validated to block open-redirect abuse.
Secrets are sealed
When you connect a tool, its credentials are encrypted with the field-level vault before they touch the database — never stored in the clear, and never exposed back to the browser.
Actions are logged
Lead activity, sequence steps, imports, sign-ins and revocations are recorded — on the lead timeline and in the security-event ledger — giving your team an attributable history of what changed and when.
Found a vulnerability? Tell us.
We welcome good-faith security research. If you believe you've found a weakness, report it privately and we'll acknowledge and prioritise it.
What to include
- A clear description of the issue and where it lives
- Steps to reproduce, with the account role involved
- Impact you believe it has, and any proof-of-concept
- Whether the finding is already public anywhere
Please give us reasonable time to investigate before any public disclosure, and never access or modify data that isn't yours.
Controls mapped to the frameworks you're audited against.
Our posture is documented and open for review — not asserted in a footnote.
Privacy law
Aligned with GDPR / UK GDPR and CCPA / CPRA: a published DPA, a sub-processor register, consent captured at registration, and data-subject rights in the privacy policy.
Security & assurance
Mapped to SOC 2 (Type II in progress) and ISO/IEC 27001 control families, with PCI-DSS-aware handling of payment flows and responsible-disclosure metadata via RFC 9116 security.txt.
Accessibility
Built toward WCAG 2.2 AA: semantic landmarks, keyboard paths, visible focus, reduced-motion support and a published accessibility statement.
We'll walk your team through it live.
Bring your security team to a consultation and we'll cover isolation, access control, data handling and export.