Contractor records, client details, and wallet balances. We take the same care with each. Plain-English overview below.
TLS in transit, AES-256 at rest. No exceptions, including backups.
Staff access to production data is role-gated and logged. Most of the team has none.
We don't handle card numbers. Payments run through [TBD provider]. Wallet ledger is append-only.
ID verification data is deleted [TBD] days after approval. Pitch recordings are not stored beyond [TBD].
Encrypted, off-region, restored on a [TBD] cadence. We practice the recovery, not just the backup.
On-call rotation, runbooks, [TBD]-hour breach-notification commitment to affected users.
We're honest about where we are. Placeholders below will be replaced with real certificate details as they land.
In progress. Audit window [TBD].
Roadmap: [TBD].
Registered controller. ICO reg [TBD].
Out of card-data scope via [TBD].
Updated as our stack changes. If you're a client or contractor, you'll see this list reflected in our DPA.
We pay for credible reports. Responsible disclosure, no live-system damage, scope at [TBD]. Email security@salesflow.[TBD] or submit via [TBD platform].
security@salesflow.[TBD]