Security

Your workspace is yours alone.

CMD-OS holds your clients, your money and your plans, so isolation and encryption are built into the foundations rather than added later.

01

Workspace isolation

  • Every table that holds your data carries a workspace ID and is protected by PostgreSQL row-level security, forced on for every table.
  • The application sets the workspace for each query inside a database transaction. A query with no workspace in scope is refused before it reaches the database.
  • Automated tests create two workspaces and prove neither can read or write the other's rows, tokens or webhook deliveries.
02

Encryption

  • All traffic to the app is served over HTTPS.
  • Credentials for services you connect — Google, GitHub, IMAP mailboxes — are encrypted with AES-256-GCM, with keys derived per purpose and bound to your workspace, and are never shown back in full.
  • Data at rest and backups are encrypted by our database provider.
03

Accounts and sessions

  • Passwords are hashed with bcrypt; we never store or see them in plain text.
  • Sessions use a signed, HttpOnly, SameSite cookie and expire after 30 days. Sign-in and sensitive actions are rate-limited.
  • Deleting your account requires your password and cancels billing, revokes Google access and removes GitHub webhooks before erasing the data.
04

AI agent access

  • Each workspace has its own MCP server URL. Apps connect through OAuth 2.1 with PKCE and a consent screen that names the app and where it sends you back.
  • Tokens are stored only as SHA-256 hashes, work only at the URL they were issued for, and rotate on every refresh; a reused refresh token revokes the connection.
  • Agents can't delete anything or change money, pipeline stage or cadence. Every connection is listed and revocable in one click.
05

Payments

  • Checkout and billing run on Stripe, a PCI DSS Level 1 provider. Card numbers never touch our servers.
06

Privacy by default

  • No analytics, advertising or tracking — in the app or on this site.
  • Lead-form IP addresses are cleared after 30 days; link-page clicks record only the referring site and country.
  • AI features are off until you turn them on, and your content is never used to train models.
07

Your control

  • Export everything as JSON at any time.
  • Delete your account and it's erased from the live database immediately and from backups within 30 days.
Security — CMD-OS