Security & data
The version your IT reviewer needs.
Controls
What is actually in place.
- Credentials
- Every third-party key you give us — Apollo, Instantly, HubSpot — is encrypted at rest with Fernet. Keys are decrypted in memory at the moment of use and never written to logs.
- Access
- Role-based access control on every account. Roles decide who can see contact data, who can send, and who can change sending settings.
- Audit log
- A full audit log of who did what and when — including sends, sequence edits, and going live. It is a record, not a feature toggle; it cannot be switched off from the UI.
- Sending limits
- 300 sends per inbox per day. This is a cap enforced in code, not a setting on a form. Nobody on your team — or ours — can raise it from the interface.
- Deployment
- Single-tenant. Each customer runs as a private instance with its own database, its own domain reputation and its own API keys. Multi-tenant self-serve is not shipped, so your data does not share a database with another agency's.
- Hosting region
- Application and database run in AWS eu-west-2 (London). Data does not leave the region in the course of normal operation.
- Sourcing method
- Hiring signal comes from sanctioned job-board APIs — Adzuna and Jooble — plus a web-search leg. We do not scrape job boards, and we do not scrape LinkedIn.
- Model cost control
- Language-model calls carry a per-call cost cap. A malformed prompt or a runaway loop cannot quietly spend your budget.
- Test Mode
- Every account starts in Test Mode. Sequences run end to end and render real messages, but nothing leaves the building. Going live requires a PIN — so an accidental click cannot email your market.
Certifications
Not SOC 2. Not ISO 27001.
We hold neither certification today, and we are not going to imply otherwise with a badge that means something else. If your procurement process requires either one right now, we are the wrong vendor and you should stop reading here.
What we can do is answer a security questionnaire honestly, in writing, with the same detail as this page.
GDPR
What “GDPR-aligned” means here.
It is a description of how the product behaves, not a certificate. Specifically:
Lawful basis
B2B outreach only. We do not process candidate data and we are not a candidate sourcer.
Opt-out
Every message carries a clear opt-out. A recipient who opts out is suppressed across all sequences on the account.
Residency
Processing and storage in AWS eu-west-2 (London).
Your keys
HubSpot sync runs on your credentials, in your HubSpot. We do not hold a copy of your CRM.
Deletion
Contact records and message history are deleted on request, and on account closure.
Something here not covered, or covered too vaguely for your reviewer? Send the questionnaire to hello@reliance-hub.com and we will answer it in writing. Or see how the pipeline works end to end.