Security & trust

What we do to protect the data you sell with.

This page is maintained by Inifye Tech Ltd to answer common security and privacy questions about Sales Intelligence. It describes the controls that are in place today. It is not a certification, an audit report, or a compliance claim.

Practices, described plainlyUpdated 2 August 2026
Shared responsibility

Who is responsible for what.

Security here is a split. We run the platform; you run how it is used; your customers get the protections both of us put in place.

Inifye

Platform security, hosting, encryption, workspace separation, credential storage, agent tracing, incident response.

You, the app owner

Who you invite, what systems you connect, what data you sync, autonomy levels, consent and opt-out handling for your own contacts.

Together

Configuring retention, agreeing residency where required, reviewing agent behaviour and access on a regular cadence.

Controls in place

What is switched on today.

Access and authentication

  • Role-based access inside each workspace, set by you.
  • Single sign-on and access review available on enterprise agreements.
  • Our own staff access is least-privilege and logged.

Platform and hosting

  • Managed cloud infrastructure with encryption in transit and at rest.
  • Each workspace's data is logically separated.
  • Change control and code review before production release.

Credentials for connected systems

  • OAuth wherever the system supports it — no passwords change hands.
  • Tokens and API keys held encrypted server-side, never in browser code.
  • Per-account revoke and reauthorise controls in the workspace.

AI controls

  • Autonomy levels and approval gates on every agent.
  • Answers grounded in your approved content and records.
  • Full run tracing: model calls, tools, retrieved records, cost and outcome.
  • Your business data is not used to train foundation models.

Logging and audit

  • Immutable audit entries with content hashes for actions taken.
  • Attribution from a customer-facing action back to the signal that caused it.
  • Exportable activity history for internal review.

Retention and deletion

  • Workspace data kept for the life of the subscription, then 30 days for export.
  • Logs retained 12 months unless your agreement says otherwise.
  • Deletion and export on request, in standard formats.
Contact

Reporting a security or privacy issue.

Email oracle@inifye.tech with what you found and how to reproduce it. We acknowledge reports, investigate, and come back with a remediation position. Please give us reasonable time before disclosing publicly, and do not access data that is not yours while testing.

Inifye Tech Ltd

Global HQ

oracle@inifye.tech

Full detail sits in the privacy notice, data processing page and AI governance page.

FAQ

Security questions we get asked

Straight answers, no certification theatre.