How we keep your sending addresses, leads, and inbox data safe.
All traffic uses TLS 1.2+. Data at rest is encrypted via Firestore's built-in envelope encryption, with row-level isolation keyed to your account.
Every API route enforces ownership: leads, sequences, and inboxes are scoped to your userId. A ForbiddenError is raised before any cross-account read.
Auth is handled by Clerk with OAuth refresh + server-side session timeout. Email verification and routing rules protect sensitive actions.
Strict transport security, a tight Content-Security-Policy, and audit logging sit in front of every request. Timing-safe comparisons guard OTP and token checks.
Found a vulnerability? Email security@convergeflow.io with details and a repro. We respond within one business day, credit responsible reporters, and won't pursue legal action for good-faith reports.
We rely on Google (Firebase), Clerk (auth), and our email-delivery providers. Each is bound by a data-processing agreement. We notify customers before engaging any new sub-processor that touches campaign data.
For SOC 2 evidence, DPA execution, or a security questionnaire, contact us or book a call.