Skip to content

Draft v1 — 6 October 2026 — pending founder approval

Security

Last updated

What we do to keep your CRM safe, stated plainly. If something here stops being true, we change this page.

Your data

  • Encrypted in transit (TLS) and at rest (AWS, through Supabase).
  • Stored in the United States, in AWS us-east-1.
  • Every query is limited to your own workspace, enforced in the database with row-level security as well as in the application.
  • Deleted records can be restored for 30 days, then they are purged.

Sign-in and connected assistants

  • You sign in with a one-time email code. There are no user passwords to leak.
  • Assistants connect with OAuth. Tokens are stored only as keyed hashes, access tokens expire after 1 hour, and refresh tokens rotate. One internal, read-only monitoring token is the only longer-lived exception, and it reads only our own test workspace.
  • You can disconnect any assistant from Settings in the dashboard.
  • The only Sambandh connector URL is https://sambandh.ai/mcp.

Logs and our access

  • Logs never contain CRM content, tool inputs, request bodies or tokens.
  • Sambandh is run by one operator. Every admin account (hosting, database, code, email, payments and domain) uses multi-factor authentication.
  • We don’t look at your CRM content except to fix a problem you report, with your permission, or when the law requires it.

Things to know

  • Sambandh cannot stop instructions hidden in your own data from steering your assistant. Your assistant asks before edits and deletes, and every change can be undone from the activity feed.
  • We are not SOC 2 or HIPAA certified. Don’t store health information in Sambandh.

If there’s a breach

If we confirm a breach affecting your data, we’ll notify you without undue delay and within 72 hours, with what we know and what you may need to tell your contacts.

Report a vulnerability

Email security@sambandh.ai with the details and steps to reproduce. Please don’t access other people’s data or disrupt the service while testing. Our security.txt has the same contact.

More on how we handle data: privacy policy and sub-processors.