Skip to content
English
  • There are no suggestions because the search field is empty.

Security and data privacy overview

Company scope and relationships

Every request operates as an active company entity. Users can belong to multiple companies and switch between them. Relationships control collaboration, while roles and feature permissions control available actions. Always verify the active company before creating, connecting, importing, or exporting data.

Limit captured data

Enable only needed applications, browsers, mailboxes, calendars, chats, phone services, and meeting recording. Pause desktop tracking for out-of-scope work. Raw heartbeat payloads can contain window titles and document names; enable them only for a justified 30-day audit need.

Protect credentials

Treat passwords, OAuth grants, API tokens, personal access tokens, client secrets, and tsk_ keys as secrets. Store them in approved secret systems, never ordinary notes or source code. Revoke or rotate them after exposure or ownership changes.

Review automation

AI suggestions, integration rules, nightly actions, and agents can create downstream records quickly. Start with review-only actions, use least privilege, and audit results. Human responsibility for billing, confidentiality, approval, and consent remains.

Respond to an incident

Pause affected capture or automation, revoke exposed access, preserve timestamps and non-secret identifiers, review created or changed records, and follow your organization's incident process.

Related articles: Understand API-key security and company scope, Review privacy before connecting communication services, Configure meeting and call recording consent.