Trust & security

Your pipeline is your business. We treat it that way.

Security isn't a page we wrote for compliance — it's the set of decisions behind every workspace, every session and every export.

Foundations

The guarantees that ship with every plan.

Org-scoped isolation

Every workspace is fully isolated. Users, leads, signals, sequences and analytics are scoped to your organisation — there is no path to another tenant's data.

Encryption in transit & at rest

Traffic is encrypted in transit, and stored integration secrets are sealed with field-level Fernet encryption (AES-128-CBC + HMAC-SHA256). The same key powers an encrypted workspace export that is useless off-platform.

Hashed credentials & lockout

Passwords are stored only as salted hashes — never in plain text. Sign-in is guarded by per-identity rate limiting and a progressive account lockout, and every attempt is written to an auth-event ledger.

Hardened sessions

Session cookies are HttpOnly, SameSite=Lax and Secure under TLS. The session rotates on login to prevent fixation, and sign-out-everywhere revokes every other cookie immediately.

Hardened request handling

Every response carries a strict Content-Security-Policy with a per-request nonce, X-Frame-Options: DENY, nosniff, a referrer and permissions policy, and HSTS when served over TLS.

No training on your data

Your leads and signals are never used to train models for other customers. Your per-workspace ranker learns only from your own outcomes.

Audit trail & accountability

Logins, lockouts, revocations and workspace actions are recorded with IP, outcome and detail — so there is always an attributable history of who did what, and when.

Data portability

Export your leads and analytics as CSV at any time, or download a sealed, encrypted workspace archive. Leave whenever you like — your data leaves with you.

In practice

What happens on every request.

You authenticate

Your password is verified against a salted hash, and a signed session is issued. Failed attempts are rate-limited, and no error reveals whether the account exists.

Your workspace is scoped

Every query is filtered to your organisation. Records from other tenants are not merely hidden — they are not part of the data returned to your request.

State changes are verified

Forms and API calls carry a CSRF token. Requests without a valid token are rejected, so a malicious page cannot act as you — and every post-login redirect is validated to block open-redirect abuse.

Secrets are sealed

When you connect a tool, its credentials are encrypted with the field-level vault before they touch the database — never stored in the clear, and never exposed back to the browser.

Actions are logged

Lead activity, sequence steps, imports, sign-ins and revocations are recorded — on the lead timeline and in the security-event ledger — giving your team an attributable history of what changed and when.

Responsible disclosure

Found a vulnerability? Tell us.

We welcome good-faith security research. If you believe you've found a weakness, report it privately and we'll acknowledge and prioritise it.

What to include

  • A clear description of the issue and where it lives
  • Steps to reproduce, with the account role involved
  • Impact you believe it has, and any proof-of-concept
  • Whether the finding is already public anywhere

Please give us reasonable time to investigate before any public disclosure, and never access or modify data that isn't yours.

Compliance

Controls mapped to the frameworks you're audited against.

Our posture is documented and open for review — not asserted in a footnote.

Privacy law

Aligned with GDPR / UK GDPR and CCPA / CPRA: a published DPA, a sub-processor register, consent captured at registration, and data-subject rights in the privacy policy.

Security & assurance

Mapped to SOC 2 (Type II in progress) and ISO/IEC 27001 control families, with PCI-DSS-aware handling of payment flows and responsible-disclosure metadata via RFC 9116 security.txt.

Accessibility

Built toward WCAG 2.2 AA: semantic landmarks, keyboard paths, visible focus, reduced-motion support and a published accessibility statement.

Questions about security?

We'll walk your team through it live.

Bring your security team to a consultation and we'll cover isolation, access control, data handling and export.