Last updated: 2026-05-06
SalesOne is the AI-orchestrated B2B outbound sales platform built by JIITAK Co., Ltd. We process two kinds of personal data: information about your team (the people who sign in) and information about your prospects (the contacts your campaigns target). Both categories are protected by the controls listed below.
| Area | Status | Detail |
|---|---|---|
| Authentication | Live | Clerk-managed sign-in with email/password and SSO options. MFA available. Internal staff use a separate Clerk organization. |
| Authorization | Live | Seven role types (admin, manager, viewer, api, sdr, account_manager, platform_admin). Every privileged route enforces requireRole; HMAC-signed role cookie verified server-side. |
| Tenant isolation | Live | PostgreSQL row-level security policies on every tenant-scoped table. The runtime app role lacks BYPASSRLS. Cross-tenant queries fail at the database layer. |
| Encryption in transit | Live | TLS 1.2+ on every external connection. HSTS preload header enforced. Strict CSP with frame-ancestors none. |
| Encryption at rest | In progress | OAuth tokens, BYOT Twilio credentials, and tenant API keys are AES-256-GCM encrypted with per-tenant keys. Column-level encryption of prospect PII (email, phone, LinkedIn) is on the immediate roadmap. |
| Audit logging | Live | Append-only audit log table records actor, IP, action, target resource, and a before/after diff for every privileged mutation. RLS-scoped read; no UPDATE/DELETE policy. |
| Webhook integrity | Live | HMAC or Svix signature verification on every webhook receiver (Stripe, Clerk, Twilio, Resend, RB2B, ElevenLabs, Unipile). Production builds refuse to accept unsigned payloads. |
| Rate limiting | Live | Sliding-window rate limits on auth, webhook, public-API, and tracking endpoints. Ring-buffered 429 events surfaced via the platform-admin observability dashboard. |
| PII stripping for AI | In progress | Personal identifiers are stripped from prompts sent to large language model providers wherever feasible. Active rollout across all AI consumers. |
| GDPR / CCPA / APPI | In progress | Privacy notice published. Data subject access and deletion requests are handled at privacy@salesone.now. End-to-end automated deletion is on the roadmap. |
| Backup & disaster recovery | Live | Neon point-in-time recovery (90-day retention). Documented runbook for restore. Vercel deploy rollback available within minutes. |
| Vulnerability management | In progress | Dependency scanning via GitHub Dependabot. Annual third-party penetration testing planned. Vulnerability disclosure program at security@salesone.now. |
| SOC2 Type II | In progress | Controls implemented; observation period running. Letter of intent available on request to enterprise prospects. |
We share personal data with the vendors below strictly to provide the Service. Each is contractually bound to security and confidentiality obligations consistent with our Privacy Policy. We notify customers at least 30 days before adding a new subprocessor.
| Vendor | Purpose | Data shared | Region | Certifications |
|---|---|---|---|---|
| Stripe | Billing & subscription | Customer + subscription identifiers, invoice metadata | US, EU, Global | SOC1/SOC2, PCI DSS Level 1, ISO 27001 |
| Clerk | Authentication & user management | User identifiers, emails, organization memberships | US | SOC2 Type II, GDPR, CCPA |
| Neon | Primary database (PostgreSQL) | All Customer Data (encrypted at rest) | AWS US-East / configurable | SOC2 Type II, ISO 27001, GDPR |
| Vercel | Application hosting & edge network | Request metadata, build logs, runtime telemetry | Global edge / function regions configurable | SOC2 Type II, ISO 27001, GDPR/CCPA |
| Inngest | Background job orchestration | Event payloads (de-identified where possible) | US | SOC2 Type II in progress |
| Anthropic | Large language model (Claude) | Structured prompts; PII stripped before submission | US | SOC2 Type II, GDPR |
| OpenAI | Large language model | Structured prompts; PII stripped before submission | US | SOC2 Type II, GDPR, CCPA |
| ElevenLabs | Voice synthesis & conversational AI | Voice prompts, conversation transcripts (per call) | US, EU | SOC2 Type II, GDPR |
| Twilio | Telephony (PSTN dialing, SMS) | Phone numbers, call SIDs, recording URLs (BYOT supported) | US, EU, Global | SOC2 Type II, ISO 27001, HIPAA, GDPR |
| Resend | Transactional & outbound email | Sender/recipient addresses, message metadata | US | SOC2 Type II, GDPR |
| FullEnrich | Prospect discovery & work-email enrichment | Search criteria; enriched contact data returned | EU | GDPR |
| Unipile | LinkedIn messaging proxy (hosted auth) | OAuth tokens, message payloads | EU | GDPR |
| RB2B | Anonymous-visitor identification | Site visitor identifiers via customer-installed pixel | US | SOC2 Type II in progress |
| Sentry | Application error monitoring | Error stack traces, user IDs, request metadata | US, EU | SOC2 Type II, ISO 27001, GDPR/CCPA |
| Upstash | Rate limiting & caching (Redis) | Rate-limit keys, ephemeral counters | Global edge | SOC2 Type II, GDPR |
We welcome responsible disclosure. Email security@salesone.now with details. We commit to acknowledging within two business days and providing a remediation timeline within ten business days. Please do not test against production customer data without prior written consent.
EU/UK (GDPR), California (CCPA), and Japan (APPI) data subjects can request access, correction, deletion, restriction, or portability by emailing privacy@salesone.now. We respond within 30 days.
Related: Privacy Policy · Terms of Service