Security
Elite Email Tracker uses tenant-scoped authorization, short-lived installation access tokens with rotating refresh credentials, role-based team permissions, optional authenticator MFA, security audit trails, rate limits, TLS, hardened non-root services, SQLite integrity checks, and tested backup/restore procedures.
Data minimization
Standard tracking sends message metadata, not message bodies. Outreach stores only content and files a user explicitly saves or sends through that feature. Network and approximate-location fields have a separately configurable retention period and can be erased while preserving aggregate engagement history. Privacy-protected and scanner signals are classified rather than presented as certain human activity.
Reporting
Report suspected vulnerabilities privately through the support contact. Do not access other users' data, disrupt service, or perform destructive testing. We acknowledge credible reports and coordinate remediation and disclosure.
Assurance status
These are implemented controls, not a claim of SOC 2, ISO 27001, or independent certification. Enterprise buyers may request current architecture, recovery, access-control, and vulnerability-management evidence under confidentiality.