Workspace isolation
Your leads, campaigns, mailboxes and analytics belong to your workspace. Access is enforced server-side on every request, not hidden in the interface.
Credentials
Provider and integration credentials are encrypted at rest and held server-side. Once stored, a key is never returned to the browser — which is why rotating means pasting a new one rather than editing the old.
Access
Sign-in is per user; a user reaches a workspace only through an explicit membership. Removing someone's membership removes their access immediately.
Important notes
The weakest link is almost always an account password or a leaked API key, not the platform. Use a password manager and rotate keys when people leave.
Was this article helpful?
