// Security

Security & data protection.

How we protect your account, your keys, and your data — in plain terms.

How we protect your data

Encrypted in transit

All traffic to the app and its APIs is served over HTTPS/TLS. Nothing moves in the clear.

Encrypted at rest

Connected API keys and OAuth tokens are encrypted at rest with AES-256-GCM before they're stored.

Hardened passwords

Passwords are stored only as salted, memory-hard scrypt hashes with constant-time verification — never in plain text.

Workspace isolation

Multi-tenant with row-level scoping: one workspace can't see another's leads, settings, keys, or inbox.

Your keys stay yours

Whether you use platform keys or bring your own (on Scale & Agency), connected keys and tokens are encrypted at rest, used only to run your jobs, and never exposed to prospects.

Least-privilege access

Session-based logins with role gating — tenant-admin controls are separated from platform-only controls.

Payments handled by Stripe

We never see or store full card numbers. Billing runs on signature-verified, idempotent Stripe webhooks.

Spend safety rails

Per-workspace budgets and a hard monthly cap pause AI automatically before spend can run away.

Transparent sub-processors

We name every third party that touches your data in our Privacy Notice, and we don't sell data.

Questions about security?

We're glad to walk through how StellarReach handles your data.

Contact us