Trust at Warm Deals
Security, privacy, and compliance posture in one place.
Last updated August 23, 2026
Compliance & Certifications
Security controls
AES-256 on all DB volumes via cloud provider keys.
TLS 1.2+ for all customer-facing endpoints.
TOTP-based MFA with backup codes, available for every account.
Per-organization OIDC SSO for enterprise tenants (Okta/Azure/Google/Auth0/generic).
Built-in roles (Owner/Admin/Manager/Member) plus per-org custom roles with permission matrix.
Append-only event log for security-relevant actions with filters and CSV export.
Email/phone/JWT/API-key/Bearer tokens are redacted from application logs.
Daily DB snapshots to MinIO with 30-day retention; restore tested.
Token-bucket limits on auth endpoints and webhook ingest.
Inbound provider webhooks verified by HMAC; outbound webhooks signed with HMAC-SHA256.
Sub-processors
| Name | Purpose | Region |
|---|---|---|
| Amazon Web Services / Hetzner | Primary infrastructure | EU |
| Cloudflare | DNS, CDN, WAF | Global |
| Stripe | Billing | Global |
| Twilio | SMS, voice | Global |
| SendGrid / Mailgun / Postmark | Email delivery | Global |
| Anthropic / OpenAI | LLM completions | US |
| ElevenLabs | Voice AI | US |
See the canonical list with full data categories and certifications on the sub-processors page.
Uptime
See live status page
Documents
- Data Processing AddendumView →
- CCPA disclosureView →
- Sub-processors listView →
- Security overview (PDF)Contact us