Security
Sales conversations are sensitive. We treat them that way.
This page describes what we have actually built. Where something is only partly done, or we are working towards a standard rather than holding it, we say so.
Data is encrypted while it travels. The full detail is in the privacy policy.
Controls
Six things worth knowing before you send us a call.
Tenant isolation
Enforced at the database
Personal information
Found and masked before anything is sent
Raw values
Keep, quarantine or shred
Access
Checked on our servers, and refused if unsure
API tokens
Hashed, scoped and revocable
Sub-processors
Named, with no-training commitments
Being precise
What we do not claim.
Not certified. We build to the areas ISO 27001 and SOC 2 cover, and we are working towards being ready. We do not hold either certificate and we will not pretend otherwise.
Stand-in labels, not strong encryption. Personal details we keep so they can be matched up later are hidden and access is restricted. That is not the same as strong encryption, and we will not call it that.
Deleting data is done by a person. Removal happens on a reviewed schedule, run by an administrator, rather than automatically. If you need data gone sooner, ask and we will do it.
Your questions
Ask us anything your security review needs.
Send security review questions our way.
If you need a security questionnaire filled in before a trial, we would rather do it up front.