This page supplements the Privacy Policy with operational detail for security, risk and compliance teams reviewing the platform.
Tenant separation
The platform separates operator access from customer access, and customer data is scoped to the organisation it belongs to. Cross-organisation access is denied by application logic, not only by user-interface hiding.
Credentials & secrets
User passwords are stored using one-way hashing. Optional authenticator-app secrets used for two-factor authentication are stored encrypted at rest. Recovery codes are stored as hashed values.
Operational logs
The platform records authentication events, transactional email send outcomes, audit events for administrative actions, and application errors needed for operational triage. These logs exist for security, support and compliance — not marketing analytics.