Server-side secrets
OAuth refresh tokens, Stripe secrets, webhook secrets and API credentials are not shipped in browser bundles.
Security and privacy
Ackvio keeps provider refresh tokens and service credentials on the server, isolates each account, denies direct customer Firestore access, and avoids retaining sent message bodies after provider acceptance.
OAuth refresh tokens, Stripe secrets, webhook secrets and API credentials are not shipped in browser bundles.
Connected mailbox, CRM, campaign and Sweep records belong to one account unless a future team feature explicitly shares them.
Backups, point-in-time recovery, monitoring and bounded retry/dead-letter handling protect the operating baseline.
Designed around real email work
Automated security checks, minimized OAuth scopes and operational safeguards are active. Independent penetration testing, legal review and any provider-required assessment remain separate external work.