Security
Plain answers for your security review.
No theater.
You're deciding whether to send a third party an export of your sales data. That deserves specifics, not badges. Here's exactly how it works. Send the hard questions to info@outreachadmin.com and you'll get written answers, usually same day.
Access: none, because we never connect
- No connection to your instance. There is no API key to issue, no OAuth grant to approve, and no login to create. We hold no credential of any kind, so there is nothing to scope, nothing to rotate, and nothing to revoke.
- You run the exports. Four standard exports that Outreach already builds, plus a few totals you read off screen and type in. All run by your own admin, in your own session. You see the exact files before you send them.
- You upload them. The files go to an intake page over TLS, one at a time, in a transfer you start and can stop at any point. Nothing is pulled from your side, on a schedule or otherwise. Your intake is reached by an unguessable link. That link lets the holder add files, see which slots are filled, and see the screen counts they typed so they can pick up where they left off. It cannot read an uploaded export back: no endpoint anywhere serves the contents of an uploaded file.
A one-click read-only connection is the eventual path and is built, but it is gated on Outreach's own app review and is not live. Until it clears, this page describes the only intake that exists.
Your data: what we hold, and for how long
- Credentials: none held, because none are issued. See the access section above.
- Your export files: they contain your sequences, templates, settings, users, and activity metadata. Files you upload through the intake are deleted automatically 30 days after upload by a storage lifecycle rule, intake session record included; files that arrive by email are deleted by hand once your audit ships. Either way, deletion sooner is one email away. Your reports keep aggregates and findings, not the raw files.
- AI analysis: audit analysis runs on Anthropic's Claude via their commercial API, which does not train on customer data. Nothing we operate trains on your data either.
- In transit: TLS everywhere.
- Who sees it: one person (Jacob Turner) and the pipeline. There are no employees, no contractors, no offshore team.
Subprocessors, the complete list
- Cloudflare · hosting, storage, delivery
- Anthropic · audit analysis (commercial API, no training on your data)
- Stripe · payments (they see billing details, never instance data)
- Resend · report email delivery (once live)
That's the whole list. If it ever changes, paying customers get notice first.
Commitments
- Breach notification: if an incident affects your data, you hear from us within 72 hours of confirmation, with specifics.
- Deletion on request: email us and your stored data (credentials, extracts, reports) is deleted, confirmed to you in writing. Uploaded extracts do not wait for the request; they expire on their own at 30 days.
- Security questionnaires: send yours to info@outreachadmin.com. Written answers, no meeting required, usually same day.
- Responsible disclosure: found something? Same address. We take it seriously and we'll credit you.
Where we are on SOC 2
Honestly: on the roadmap, triggered by customer demand, not yet audited. We're a one-operator company with a deliberately tiny surface area, and we'd rather tell you exactly how the system works today than wave a badge. If your review needs our current questionnaire answers or a DPA, ask and you'll have them fast.