Security

How we protect your customer datastated plainly.

This page lists the controls that exist in the product today, and the ones that don't yet. If something is unclear, write to our security team.

AES-256-GCM for stored credentialsWorkspace isolationSSO + SCIM
Defence in layers

Five layers between your data and everyone else

  1. 01
    EncryptionMailbox tokens, integration keys and payment secrets are encrypted with AES-256-GCM.
  2. 02
    Workspace isolationEvery query is scoped to your workspace. A workspace id sent by a client is ignored.
  3. 03
    Access controlRoles with own, team or all scope, per-person overrides and an audit log.
  4. 04
    IdentitySSO over SAML 2.0 or OpenID Connect, SCIM provisioning, bcrypt-hashed passwords.
  5. 05
    Network edgeHTTPS, signed inbound webhooks, and outbound webhooks that refuse private addresses.
Encryption

Secrets stay encrypted, and stay out of sight

What we encrypt, how we store passwords and tokens, and how data moves.

At rest

Stored credentials

OAuth tokens for connected mailboxes and calendars, API keys you paste for integrations, and Stripe or Razorpay secrets are encrypted with AES-256-GCM and a random IV per value. After you save a key, the app never shows it again.

Hashing

Passwords and tokens

Passwords are hashed with bcrypt at cost 12. Password-reset links, invite codes and API keys are stored as hashes, so a database copy does not reveal them.

In transit

HTTPS everywhere we send

The app is served over HTTPS. Outbound webhooks only go to HTTPS addresses. Session cookies are httpOnly, Secure and SameSite=strict.

Recordings

Call recordings

Every call recording is stored encrypted, and recordings past your jurisdiction's retention period are deleted automatically.

Sessions

Short-lived access

The access token lives in memory, not in browser storage. Refresh tokens rotate on use, and reuse of an old one is detected.

Database

Disk-level encryption

Confirm the hosting provider's volume encryption before stating it here. placeholder: verify before publishing

Access control

Each person sees what their role allows

Roles decide scope and actions. Single sign-on and SCIM keep the team list in step with your identity provider.

Roles

Five built-in roles

Admin, Super User, Manager, Employee and Restricted. Each feature has View Own, View Team and View All, plus create, edit and delete. Records outside your scope return "not found". Custom roles come with the Scale plan.

Overrides

One-off exceptions

An admin can Grant or Deny a single capability for one person without making a new role. Nobody can change their own role.

Fields

Field-level permissions

Choose which roles may edit each custom field. The API can also hide selected sensitive values, such as a contact's phone or a deal's value, from roles you name. A settings screen for those read rules is not out yet.

SSO

Single sign-on

Connect an identity provider over SAML 2.0 or OpenID Connect and map its groups to roles. People managed by SSO cannot sign in with, or reset, a local password.

SCIM 2.0

Provisioning

Create, update and deactivate users and groups from your identity provider. Group changes recompute the person's role. Deprovisioning deactivates the account and keeps their records.

Audit

Audit log

Admins see recent activity under Settings → Audit Log and choose how long entries are kept before they are deleted.

Data rights

GDPR tools, and what is still manual

On the Growth and Scale plans, you can record requests and consent and set retention per jurisdiction. Some steps still need a person.

What the product does

  • Logs a right-to-erasure request on a lead, with the requester's email and date, and shows when deletion is due (30 days).
  • Adds a GDPR consent checkbox to your web forms. Each submission keeps the acceptance, the time and the sender's network address.
  • Sets consent-record and recording retention per jurisdiction, from 1 to 36,500 days.
  • Produces a compliance bundle PDF for a lead: consent records, compliance events and call audits.

What you do by hand today

  • Verify the requester's identity. No verification email is sent yet.
  • Delete the lead when the request is valid. Deletion after 30 days is not automatic yet.
  • Answer access or portability requests. There is no one-click export of everything held about one person yet.

Need help with a request? Write to us and we'll walk you through it. placeholder: privacy@ address

Infrastructure

How the platform is put together

Guards at the edges, where data comes in and goes out.

Tenancy

Workspace isolation

Every query for customer data carries your workspace id, taken from your session. A workspace id in a request body is stripped. Plans and feature flags change only from our admin console.

Inbound

Signed webhooks

Webhooks from calling, messaging and payment providers are checked against the provider's signature before we act on them.

Outbound

No calls into private networks

Outbound webhook URLs must be HTTPS, and internal or private IP ranges are blocked.

Uploads

Files

Storage keys are generated by the server, not chosen by the uploader, and SVG uploads are blocked.

Errors

No stack traces

Errors return a generic message. Details stay in server-side logs.

Browser

Secrets stay on the server

No secret keys are shipped to the browser or kept in source control. The web app sanitises HTML before it displays it.

Not yet

What we don't have

  • No SOC 2 or ISO 27001 certification. We will say so here when an audit is complete.
  • No built-in two-factor sign-in for workspace users. If you need it now, sign in through SSO and enforce MFA in your identity provider.
  • Hosting provider and data region. placeholder: confirm before publishing
Responsible disclosure

Found a security issue? Tell us first.

We want to hear about it. Send the details privately and give us a reasonable time to fix it before you share it.

security@pitch2sale.com placeholder
  1. Describe the issue, the steps to reproduce it and what an attacker could do.
  2. Use only your own test workspace. Don't access, change or delete other customers' data.
  3. Don't run denial-of-service tests or send spam through the product.
  4. We'll confirm receipt and keep you updated until it's fixed. placeholder: response time

Last reviewed October 2026.