Security
Last updated September 2026
Secrets management
All credentials live in environment variables or a vault with least-privilege scopes — never in source, logs, or the client bundle.
Encryption
TLS everywhere in transit. At rest, the credentials you entrust us with — mailbox passwords, OAuth refresh tokens and DKIM signing keys — are encrypted with AES-256-GCM under a key held outside the database, and rotated without downtime.
Access control
Role-based access gates campaigns and raw contact data. Sessions use secure, HTTP-only cookies.
Webhooks
Inbound webhooks (Twilio, email providers) are signature-verified before their payloads are trusted.
Reporting
Found an issue? Email security@followthroo.com — we respond quickly and credit responsible disclosure.
This is a template document for Followthroo and not legal advice. Replace with counsel-reviewed text before launch.