Security

Built to protect
every brand's data.

Security is built into the foundation: encrypted credentials, a hardened API boundary, scoped access, and tenant isolation.

Permission first. Every brand distinct.
How we protect you

Security fundamentals

01

Encrypted credentials

Provider passwords, tokens, and webhook secrets are submitted only to dedicated endpoints and encrypted server-side. They are never returned by the API or bundled into browser code.

02

A hardened API boundary

The API can only address an explicit allow-list of tables and fields. Secret, credential, event, and generated-version tables are deliberately unreachable.

03

Scoped access

Granular roles, per-brand membership scopes, and live/test API keys with per-key scopes and expiry keep access least-privilege by default.

04

Permission-first by design

Bounce, complaint, and unsubscribe processing can never be turned off — consent enforcement is structural, not a setting.

05

Tenant isolation

Every record is tenant- and brand-scoped, so data never crosses between the brands or organizations that own it.

06

Operational visibility

Incidents, risk events, and background jobs are tracked, so problems surface instead of hiding.

Bring your provider.
Keep your brands distinct.
Start today.

Set up your first workspace, connect a provider, and publish a workflow — free, in test mode, before you pay a thing.