Trust

Last updated: 2026-05-06

SalesOne is the AI-orchestrated B2B outbound sales platform built by JIITAK Co., Ltd. We process two kinds of personal data: information about your team (the people who sign in) and information about your prospects (the contacts your campaigns target). Both categories are protected by the controls listed below.

Security controls

AreaStatusDetail
AuthenticationLiveClerk-managed sign-in with email/password and SSO options. MFA available. Internal staff use a separate Clerk organization.
AuthorizationLiveSeven role types (admin, manager, viewer, api, sdr, account_manager, platform_admin). Every privileged route enforces requireRole; HMAC-signed role cookie verified server-side.
Tenant isolationLivePostgreSQL row-level security policies on every tenant-scoped table. The runtime app role lacks BYPASSRLS. Cross-tenant queries fail at the database layer.
Encryption in transitLiveTLS 1.2+ on every external connection. HSTS preload header enforced. Strict CSP with frame-ancestors none.
Encryption at restIn progressOAuth tokens, BYOT Twilio credentials, and tenant API keys are AES-256-GCM encrypted with per-tenant keys. Column-level encryption of prospect PII (email, phone, LinkedIn) is on the immediate roadmap.
Audit loggingLiveAppend-only audit log table records actor, IP, action, target resource, and a before/after diff for every privileged mutation. RLS-scoped read; no UPDATE/DELETE policy.
Webhook integrityLiveHMAC or Svix signature verification on every webhook receiver (Stripe, Clerk, Twilio, Resend, RB2B, ElevenLabs, Unipile). Production builds refuse to accept unsigned payloads.
Rate limitingLiveSliding-window rate limits on auth, webhook, public-API, and tracking endpoints. Ring-buffered 429 events surfaced via the platform-admin observability dashboard.
PII stripping for AIIn progressPersonal identifiers are stripped from prompts sent to large language model providers wherever feasible. Active rollout across all AI consumers.
GDPR / CCPA / APPIIn progressPrivacy notice published. Data subject access and deletion requests are handled at privacy@salesone.now. End-to-end automated deletion is on the roadmap.
Backup & disaster recoveryLiveNeon point-in-time recovery (90-day retention). Documented runbook for restore. Vercel deploy rollback available within minutes.
Vulnerability managementIn progressDependency scanning via GitHub Dependabot. Annual third-party penetration testing planned. Vulnerability disclosure program at security@salesone.now.
SOC2 Type IIIn progressControls implemented; observation period running. Letter of intent available on request to enterprise prospects.

Subprocessors

We share personal data with the vendors below strictly to provide the Service. Each is contractually bound to security and confidentiality obligations consistent with our Privacy Policy. We notify customers at least 30 days before adding a new subprocessor.

VendorPurposeData sharedRegionCertifications
StripeBilling & subscriptionCustomer + subscription identifiers, invoice metadataUS, EU, GlobalSOC1/SOC2, PCI DSS Level 1, ISO 27001
ClerkAuthentication & user managementUser identifiers, emails, organization membershipsUSSOC2 Type II, GDPR, CCPA
NeonPrimary database (PostgreSQL)All Customer Data (encrypted at rest)AWS US-East / configurableSOC2 Type II, ISO 27001, GDPR
VercelApplication hosting & edge networkRequest metadata, build logs, runtime telemetryGlobal edge / function regions configurableSOC2 Type II, ISO 27001, GDPR/CCPA
InngestBackground job orchestrationEvent payloads (de-identified where possible)USSOC2 Type II in progress
AnthropicLarge language model (Claude)Structured prompts; PII stripped before submissionUSSOC2 Type II, GDPR
OpenAILarge language modelStructured prompts; PII stripped before submissionUSSOC2 Type II, GDPR, CCPA
ElevenLabsVoice synthesis & conversational AIVoice prompts, conversation transcripts (per call)US, EUSOC2 Type II, GDPR
TwilioTelephony (PSTN dialing, SMS)Phone numbers, call SIDs, recording URLs (BYOT supported)US, EU, GlobalSOC2 Type II, ISO 27001, HIPAA, GDPR
ResendTransactional & outbound emailSender/recipient addresses, message metadataUSSOC2 Type II, GDPR
FullEnrichProspect discovery & work-email enrichmentSearch criteria; enriched contact data returnedEUGDPR
UnipileLinkedIn messaging proxy (hosted auth)OAuth tokens, message payloadsEUGDPR
RB2BAnonymous-visitor identificationSite visitor identifiers via customer-installed pixelUSSOC2 Type II in progress
SentryApplication error monitoringError stack traces, user IDs, request metadataUS, EUSOC2 Type II, ISO 27001, GDPR/CCPA
UpstashRate limiting & caching (Redis)Rate-limit keys, ephemeral countersGlobal edgeSOC2 Type II, GDPR

Reporting a vulnerability

We welcome responsible disclosure. Email security@salesone.now with details. We commit to acknowledging within two business days and providing a remediation timeline within ten business days. Please do not test against production customer data without prior written consent.

Data subject requests

EU/UK (GDPR), California (CCPA), and Japan (APPI) data subjects can request access, correction, deletion, restriction, or portability by emailing privacy@salesone.now. We respond within 30 days.

Related: Privacy Policy · Terms of Service