Security
The controls that protect your account, your data and your customers.
Human in the loop
Anything high-risk, sending a reply, booking a meeting, writing to a connected system, pauses for a person to approve, edit or reject. An AI employee cannot take a sensitive action on its own.
Tenant isolation
Every request is scoped to your organization and verified against your membership on the server. One customer can never read or act on another's data.
Credentials and secrets
Connected tokens (Google, HubSpot, Slack and others) are encrypted at rest and never sent to the browser or written to logs. You grant access through each provider's own consent screen and can revoke it at any time.
Accounts and sessions
Passwords are hashed with Argon2. Sessions use random tokens stored only as a keyed hash, sent as HttpOnly, Secure, SameSite cookies, and can be revoked. Sign-in and public forms are rate-limited against abuse.
Auditability
Every decision and action an employee takes is logged and reversible, so you always have a full trail of what happened and why.
Report an issue
Found a vulnerability? Email [email protected] and we'll respond quickly. Please give us a chance to fix it before disclosing publicly.