Security
Security is built into how the product is structured: private routes, scoped data access, server-side handling of credentials, and a small, audited set of providers.
Account security
Passwords are hashed with industry-standard algorithms and never stored in plain text. Sign-in links expire after 15 minutes. Sessions use secure, HTTP-only cookies.
Data isolation
Every lead, run, and connection row is tied to a workspace and protected by row-level security in the database. One customer can never read another customer's data, even if application code has a bug.
Credentials and integrations
Your Apify token is verified and stored server-side, encrypted at rest, and never sent back to the browser after saving. All calls to Apify and Stripe happen from our servers.
Infrastructure
The application runs on Vercel with TLS everywhere. The database is hosted by Supabase with encrypted storage and daily backups. Security headers, strict referrer policy, and frame protection are set on every response.
Reporting a vulnerability
If you find a security issue, email aminemebarki130813@gmail.com with the details. We acknowledge reports within two business days and do not pursue legal action against good-faith researchers.
Start filling your pipeline today
14-day free trial. No credit card required. Cancel anytime.