On this page
Separation between companies
Every record belongs to exactly one company workspace, and that ownership is enforced in the database itself rather than by the screens on top of it. A request that asks for another company’s data does not get it, however it is made.
Accounts and access
- Sign-in is handled by a dedicated authentication provider. We never see or store your password.
- Inside a company there are two levels: an admin who sets the buyer profile and manages the team, and employees who work inside it.
- An account can be archived immediately, which ends access while leaving the work it created intact.
Mailbox credentials
If you connect a mailbox, its password is encrypted with a key held outside the database, and it is never displayed back to anyone - not to you, and not to us. A leaked copy of the database on its own would not let anybody send mail as you.
In transit and at rest
Traffic to the service is encrypted in transit. Data at rest sits with our database and hosting providers, encrypted under their platform controls and backed up on their schedule.
What we deliberately do not hold
- Card numbers - payments are not taken on this site.
- Passwords in readable form, for your account or for a connected mailbox.
- Personal data about the contacts our customers reach, beyond published workplace details.
Reporting a vulnerability
Write to security@samoraone.com with enough detail to reproduce it. We will confirm receipt, keep you updated while we fix it, and credit you if you would like that.
Please do not run automated scans against the live service, do not access or alter data that is not yours, and give us a reasonable chance to fix the issue before publishing it. Report in good faith and we will not pursue you for it.
If something goes wrong
If a breach affects your data we will tell you what happened, what it touched and what we are doing about it, without waiting until the story is tidy. Where the law requires us to notify a regulator, we will.