OUTREACHADMIN

Security

Plain answers for your security review.
No theater.

You're deciding whether to send a third party an export of your sales data. That deserves specifics, not badges. Here's exactly how it works. Send the hard questions to jacob@outreachadmin.com and you'll get written answers, usually same day.

Access: there isn't any

  1. No connection to your instance. There is no key to hand over and no login to create. Nothing of ours ever authenticates against your Outreach account, so there is no access to scope, monitor, or revoke.
  2. You run the exports yourself. We send a click-by-click list of standard exports available in your own admin. You run them, you look at the files, and you send them. You see exactly what is leaving before it leaves.
  3. You can stop at any point. Nothing is automated on your side, so stopping means not sending the next file. There is no exit process and no email required.

A one-click read-only connection is the eventual path and is built, but it is gated on Outreach's own app review and is not live. Until it clears, this page describes the only intake that exists.

Your data: what we hold, and for how long

  1. Credentials: none are collected, because none are needed. There is no token and no key, so there is nothing of yours to encrypt, store, or leak.
  2. Your export files: they contain your sequences, templates, settings, users, and activity metadata. They arrive by email, are kept only as long as it takes to produce your audit, and are deleted on request. Your reports keep aggregates and findings, not the raw files.
  3. AI analysis: audit analysis runs on Anthropic's Claude via their commercial API, which does not train on customer data. Nothing we operate trains on your data either.
  4. In transit: TLS everywhere.
  5. Who sees it: one person (Jacob Turner) and the pipeline. There are no employees, no contractors, no offshore team.

Subprocessors, the complete list

  1. Cloudflare · hosting, storage, delivery
  2. Anthropic · audit analysis (commercial API, no training on your data)
  3. Stripe · payments (they see billing details, never instance data)
  4. Resend · report email delivery (once live)

That's the whole list. If it ever changes, paying customers get notice first.

Commitments

  1. Breach notification: if an incident affects your data, you hear from us within 72 hours of confirmation, with specifics.
  2. Deletion on request: email us and your stored data (credentials, extracts, reports) is deleted, confirmed to you in writing.
  3. Security questionnaires: send yours to jacob@outreachadmin.com. Written answers, no meeting required, usually same day.
  4. Responsible disclosure: found something? Same address. We take it seriously and we'll credit you.

Where we are on SOC 2

Honestly: on the roadmap, triggered by customer demand, not yet audited. We're a one-operator company with a deliberately tiny surface area, and we'd rather tell you exactly how the system works today than wave a badge. If your review needs our current questionnaire answers or a DPA, ask and you'll have them fast.