Security and trust

Your company brain deserves serious protection.

Salesa brings sensitive deal context into one operating system. We protect that context with encryption, strict account isolation, minimum access, and controls designed around how deal teams actually work.

Last reviewed October 3, 2026

Core controls

Protection across the system

Encryption by default

Data is encrypted in transit using HTTPS and TLS. Stored application data is protected by encryption at rest through our infrastructure providers.

Customer data isolation

Database level access controls separate each company account. Users can access only the records permitted by their account membership and role.

Protected connection credentials

Work account credentials remain on the server. Connection secrets stored by Salesa are encrypted with AES 256 GCM and are never exposed to browser code.

Role based access

Managers and reps receive different permissions. Sensitive actions are checked against authenticated identity and account membership before data is returned.

Minimum necessary access

Connected services use the narrowest permissions needed for enabled features. Google connections are read only, and selected Drive access is limited to files a user chooses.

Controlled retention

Customers can disconnect a source and request deletion. Connected Google data is deleted on request after disconnection and within 30 days after account closure.

Infrastructure assurance

Precise claims. No borrowed badges.

Salesa runs on cloud and database infrastructure maintained by providers with established security programs. Certain infrastructure providers publish independent SOC 2 Type II reports and ISO 27001 certifications for their own services.

Those provider attestations support the systems Salesa uses, but they do not mean Salesa itself is independently SOC 2 Type II certified or ISO 27001 certified. Salesa will only claim its own certification after completing the applicable independent audit.

Salesa is built on security reviewed infrastructure. It does not present provider certifications as its own.

AI and connected data

Your context stays your context

Salesa processes business text to produce summaries, deal signals, risks, forecasts, coaching, and next actions. Access to connected sources is limited to the features a user enables.

We do not sell personal information or connected account data.

We do not use Google user data to train generalized AI models.

We do not share raw deal content with unrelated customers.

We do not request permission to send, modify, or delete Google mail, calendar events, or files.

Operational security

Prevention and response

Salesa uses restricted credential access, authenticated server checks, input validation, and audit history for sensitive deal actions.

Incident response

Clear communication

If a security incident compromises personal data, affected users will be notified without undue delay and in accordance with applicable law.

Responsible disclosure

Report a concern

If you believe you found a security issue, email us with the affected page, steps to reproduce it, and potential impact. Please do not access data that is not yours.

supportsalesa.io@gmail.com

Need a deeper security review?

We can answer security, privacy, data handling, and connected account questions for your organization.