Trust

Security

How we keep your sending addresses, leads, and inbox data safe.

Encryption in transit & at rest

All traffic uses TLS 1.2+. Data at rest is encrypted via Firestore's built-in envelope encryption, with row-level isolation keyed to your account.

Per-account data isolation

Every API route enforces ownership: leads, sequences, and inboxes are scoped to your userId. A ForbiddenError is raised before any cross-account read.

Authentication

Auth is handled by Clerk with OAuth refresh + server-side session timeout. Email verification and routing rules protect sensitive actions.

Security headers & CSP

Strict transport security, a tight Content-Security-Policy, and audit logging sit in front of every request. Timing-safe comparisons guard OTP and token checks.

Responsible disclosure

Found a vulnerability? Email security@convergeflow.io with details and a repro. We respond within one business day, credit responsible reporters, and won't pursue legal action for good-faith reports.

Sub-processors

We rely on Google (Firebase), Clerk (auth), and our email-delivery providers. Each is bound by a data-processing agreement. We notify customers before engaging any new sub-processor that touches campaign data.

What we don't do

  • We don't store raw passwords — auth is delegated to Clerk.
  • We don't sell or share your leads or contact lists with third parties.
  • We don't deploy tracking pixels or third-party analytics on the marketing site.

Need a security review?

For SOC 2 evidence, DPA execution, or a security questionnaire, contact us or book a call.