Security

Your sales data, protected by design

Your team's leads, sales and numbers are sensitive information. Security isn't an add-on: it's built into the database, the integrations and every login.

Workspace isolation

Every table enforces row-level security (RLS) policies. Each query is scoped to your workspace in the database itself, not just in the application.

Access and permissions

Everyone signs in with their own account, with optional two-step verification, and a role: admin or member. Settings, team, integrations and expenses are managed by admins only.

Keys we don't store

API and export keys are shown only once. Only their SHA-256 hash is stored, and they are compared in constant time. Regenerating a key revokes the previous one instantly.

Signed webhooks

Every notification is signed with HMAC-SHA256 over the payload and timestamp, so your system can verify its origin and integrity. Retries keep the same delivery ID.

Encryption

Connections are always encrypted with HTTPS and HSTS. The database runs on managed infrastructure with encryption at rest.

Abuse protection

Rate limits on the public API, exports, sign-up, bookings and reports to stop brute-force attacks and misuse.

Hardened application

Security headers against clickjacking and content sniffing. Internal database functions cannot be invoked from the browser.

Your data is yours

Export leads, sales, bookings and more to CSV at any time, including before you cancel. No lock-in, no closed formats.

Responsible disclosure

If you find a vulnerability, please contact us before making it public. We respond to every report and keep you informed of the fix.

Report a vulnerability

Get your sales team in order today.

Create your workspace, invite your team and start measuring in minutes.