⛁
Encrypted in transit and at rest
TLS 1.3 on every connection, AES-256 on stored data. Credentials for connected tools are encrypted separately with per-workspace keys, so a leak of one is not a leak of all.
◉
Roles that actually restrict
Owner, admin, agent and viewer. A viewer cannot send anything or spend a credit. An agent works inside your guardrails and caps and cannot raise them. Enforced server-side, not hidden in the UI.
⇄
Least-privilege integrations
Read-only where reading is enough. The ad platforms get analysis access, not spend access. Every scope is listed before you approve it and revocable in one click.
✕
Never used to train
Your contacts, conversations and outcomes are not training data for anyone — not us, not a model vendor, not another customer. It is contractual, not a policy page.
▤
Exportable on demand
Contacts, conversations, outcomes and the full ledger, as CSV, whenever you want. No support ticket, no retention negotiation.
◫
Durable execution
Campaigns run on a workflow engine that survives restarts, so a deploy mid-campaign cannot double-send or silently drop a step.