Security and data

Your account, your data, your call.

This product acts on a real LinkedIn account and holds real information about real people. Both deserve stating plainly rather than a badge.

We never see your LinkedIn password

Connecting an account happens on the provider's own hosted page. What comes back is a token bound to your workspace, not a credential we could sign in with.

Tokens are encrypted before they are stored

Every OAuth credential — LinkedIn, calendar, CRM — is encrypted with AES-256-GCM before it touches the database, using a key held only by the worker. A copy of the database on its own is not enough to act as you.

One workspace cannot read another

Every table carrying customer data has row-level security keyed to workspace membership, enforced by the database rather than by application code remembering to filter.

A prospect can be erased

One click removes a person and everything written about them, and records that they must not be contacted again — the record of the erasure is the only thing that survives it, because otherwise the next campaign would find them afresh.

Retention is a limit, not a promise

Prospect data older than the workspace's retention window is deleted by a nightly sweep, whether or not anyone remembers to ask.

Every message is attributable

Each sent message records the prompt version that produced it. If a campaign starts saying something wrong, the change that caused it is one query away.

What we do not claim. We are not SOC 2 audited and we do not say we are. Ask us again when we have a report to hand you, and in the meantime take this page as the honest version.

The other half of safety is not losing the account in the first place — that is on the limits page.

Start with ten invitations a day.

Seven days free, no card. Your first campaign runs in approval mode, so nothing reaches anyone until you have read it.