Skip to content

Security & privacy

EU-hosted, permission-scoped, and honest about what we do not have

Outbound work means handling personal data about people who did not choose to be in your database. That deserves a clear answer about where the data lives, who can reach it, and how long it stays.

EU data residency by construction

All infrastructure runs in AWS eu-central-1 (Frankfurt). Product analytics are on PostHog EU cloud and error monitoring is on the EU region. This is where the system is built, not a region toggle.

Scope by permission, not by job title

The all-versus-rostered data decision keys off explicit permissions rather than role, so a contractor SDR restricted to their own projects and an employee with full visibility can hold the same role and differ only by permission template.

Tenant isolation on every path

Tenant is resolved from a request header and validated by middleware, which attaches the account before any handler runs. Authorisation then verifies account membership. Cross-tenant access is a middleware concern, not something each route remembers.

Validated input everywhere

Request and response shapes are validated with Zod schemas rather than trusted, so malformed or unexpected payloads are rejected at the boundary.

Documented retention and erasure

GDPR retention policy, right-to-be-forgotten procedure and outbound email compliance notes are maintained in the repository alongside the implementation, so the policy and the code change together.

Short clocks on sensitive data

Call recordings and transcripts are treated as high-sensitivity personal data, with automated archival and cleanup jobs rather than indefinite retention.

Engineering practice

The guarantees that protect the money

Most of what makes a billing system trustworthy is not a feature. It is the set of invariants that hold when a job retries, a queue redelivers or a process dies mid-write.

Events published after commit

A domain event is never emitted before the database transaction that justifies it commits, so no consumer ever reacts to something that was rolled back.

Transactional outbox

Events are written to an outbox table and published by a drainer, so a crash between the commit and the broker cannot lose an event.

Idempotent consumers

Processed messages are tracked per (message id, consumer), so an at-least-once redelivery cannot double-handle. Money paths additionally carry database-level unique constraints.

Schema before code

CI applies database migrations before deploying the application, and a migration failure blocks the deploy rather than leaving code running against an older schema.

Secrets out of source

Opaque secrets live in the CI secret store and are synced to the runtime environment at deploy time; infrastructure-derived values come from Terraform. Neither is committed.

Pinned dependencies

Every dependency across every workspace is pinned to an exact version, so CI, production and a developer machine cannot resolve to different code.

Questions

Including the awkward ones

Do you hold SOC 2 or ISO 27001?
No. We are not going to imply otherwise on a marketing page. A security audit before production go-live is a stated requirement for the platform, and we are happy to walk through the architecture, the data model and the access controls in detail with your security team. If a certification is a hard procurement requirement today, we are not the right choice yet.
Where exactly is the data?
AWS eu-central-1 (Frankfurt) for application infrastructure and the database, PostHog EU cloud for product analytics, and the Sentry EU region for error monitoring. If a sub-processor list is needed for your own records, ask and we will provide the current one.
How is a deletion request handled?
A right-to-be-forgotten procedure is documented in the repository. The practical complexity is that an SDR operation spreads personal data across the prospect record, the activity timeline, call recordings, transcripts, calendar entries and any CRM the booking was pushed into — so the procedure is built around a known data map. Aggregate figures that no longer identify anyone, and the minimal record needed to keep honouring a contact objection, are deliberately retained.
Can our clients see each other’s data in the portal?
No. Portal users hold client-scoped roles and see only their own account: their meetings, reports, billing and DNC list. They cannot see your other clients, your rosters, your rep commissions or your margins. Scope is enforced by tenancy and permission rather than by which URL they were given.
What about call recording consent?
Recording obligations differ by country — some jurisdictions require all parties to consent rather than one — so a multi-country operation cannot assume a single policy covers it. The platform supports recording with retention controls; the lawful basis and notification practice for your markets is yours to set, and worth taking advice on.
Is there an audit trail?
Activity is append-only per lead, booking history is recorded through a dedicated consumer, and commission rows carry explicit lifecycle states rather than being mutated in place. Admin impersonation exists for support access. If you need a specific audit export for a compliance process, raise it — we would rather know the requirement than guess.

Book a walkthrough

Send us your security questionnaire

We would rather answer it properly than publish a trust badge. Architecture, data model and access controls, walked through with your team.

EU-hosted · eu-central-1 · integrates the CRM, calendar and telephony you already run