Security and data handling

Specific controls. Clear boundaries. No borrowed trust badges.

This page describes controls that are represented in SleekSync's current architecture and codebase. It also says where customer responsibility begins and which certifications we do not claim.

Controls you can ask us to explain

Security built into the service boundary

We focus on data separation, least-privilege access, payment isolation, and traceable privileged activity.

Tenant-scoped data access

Sensitive database tables use row-level security policies tied to authenticated users and their tenant. High-risk tables also force those policies at the database layer.

Roles and permissions

Account access is authenticated, and product permissions are scoped to the user and tenant instead of relying on hidden interface controls alone.

Audited support access

Privileged support workflows are designed around time-bounded, read-only access with recorded approval and audit events for sensitive actions.

Encrypted transport

SleekSync production web traffic uses HTTPS so data is encrypted while moving between supported browsers and the service.

Stripe-hosted checkout

Subscription payment credentials are submitted through Stripe Checkout. SleekSync uses the resulting billing status and does not need your complete card number.

Fail-closed public forms

Public lead and trial surfaces are separated from private records, with server-side validation, rate-limiting support, and insert-only database policies where applicable.

Shared responsibility

What your team controls

The strongest platform controls cannot compensate for excessive permissions, shared credentials, or unnecessary customer data.

  • Use a unique password and protect every account that can access your workspace.
  • Give staff the minimum role and permissions needed for their work.
  • Remove former employees promptly and review shared devices and browser sessions.
  • Collect customer information lawfully and avoid entering unnecessary sensitive data.
  • Review AI-assisted suggestions, taxes, fees, refunds, and customer commitments before acting.

Report a security concern

Send the affected URL, a clear description, reproduction steps, and your contact information. Do not include customer records, passwords, secret keys, or payment credentials in email.

[email protected]

Privacy or data request

For access, correction, export, or deletion questions, use the privacy channel. End customers should normally begin with the shop that controls their rental relationship.

[email protected]