Your pipeline is your business.
A CRM holds your customer list, your deal sizes, and your next moves. Here's exactly how IronVail protects them, in plain language and with no badge theater.
Your workspace is isolated at the database level
Every workspace lives behind PostgreSQL row-level security. Isolation is enforced by the database itself on every query, not by application code remembering to filter. Another customer's request physically cannot return your rows.
Team access is role-based (owner / member), and profile and billing records can only be changed through audited database functions, never by direct writes from a browser session.
Mailbox connections take the minimum, keep nothing readable
Connecting Microsoft 365 requests only the scopes outreach needs: sending mail and reading message metadata for reply detection. We deliberately do not request full mailbox read/write. We can't read your email bodies, and neither could anyone who compromised us.
OAuth tokens are encrypted at rest with a key that lives outside the database. Disconnecting a mailbox removes access immediately, and a teammate leaving the workspace revokes their mailbox connection with them.
Your data is yours — provably
Any member can export any list as CSV. A workspace owner can export everything — every table, with IDs and relationships intact, re-importable here or anywhere else. Credentials and tokens are excluded from exports by construction: the export code works from an explicit column whitelist, so a secret can't leak into a zip by accident.
There's no exit tax and no 'talk to us to get your data.' When a trial ends, nothing is deleted; the workspace just locks until an owner subscribes.
Who we build on
IronVail runs on a small, named set of subprocessors: Supabase (database and authentication), Vercel (hosting), Stripe (billing — card numbers never touch our servers), and Resend (transactional email). Each is listed in our privacy policy with what they process.
Honest limits
We're a young product and we won't pretend otherwise: we don't yet hold a SOC 2 or ISO 27001 certification. What we can show today is architecture (database-enforced isolation, minimal scopes, encrypted secrets, whitelisted exports) and a support team that answers. If your security review needs specifics, ask us anything via the in-app support widget.
Details on what we collect and why live in the privacy policy.
Stop letting deals go cold.
Your pipeline already knows which deals need you. Tomorrow morning, let it tell you.