Security
Gatrevo connects to your CRM, sequencer, and communication tools. We take the responsibility of handling those credentials seriously.
Encryption in transit and at rest
All traffic between your browser and Gatrevo is encrypted with TLS 1.3. Data at rest — including campaign records, contact lists, and integration credentials — is encrypted with AES-256.
Credential storage
API keys and tokens you connect (Slack, HubSpot, Apollo, etc.) are stored in a secrets management system, separate from the main database. They are never logged in plaintext.
Access controls
Role-based access (Owner, Admin, Member) limits what each user can view and modify. All authenticated requests require a short-lived JWT. Refresh tokens are stored as httpOnly cookies.
Audit logs
Enterprise plans include full audit logs of gate approvals, connector changes, and admin actions. Logs are immutable and exportable.
Responsible disclosure
If you discover a security vulnerability, please report it to security@gatrevo.ai. We will acknowledge your report within 48 hours and work with you to address the issue. We do not pursue legal action against researchers who follow responsible disclosure practices.