Security and privacy

Protect access, minimize data, state limitations clearly.

Ackvio keeps provider refresh tokens and service credentials on the server, isolates each account, denies direct customer Firestore access, and avoids retaining sent message bodies after provider acceptance.

Server-side secrets

OAuth refresh tokens, Stripe secrets, webhook secrets and API credentials are not shipped in browser bundles.

Private by default

Connected mailbox, CRM, campaign and Sweep records belong to one account unless a future team feature explicitly shares them.

Recovery controls

Backups, point-in-time recovery, monitoring and bounded retry/dead-letter handling protect the operating baseline.

Designed around real email work

Technical safeguards are not a certification claim.

Automated security checks, minimized OAuth scopes and operational safeguards are active. Independent penetration testing, legal review and any provider-required assessment remain separate external work.