Trust

Security

Last updated 12 September 20267 sections

What we do to keep accounts and data safe, said plainly and without the usual badge collection. If you have found a problem, the last section is the one you want.

On this page
  1. Separation between companies
  2. Accounts and access
  3. Mailbox credentials
  4. In transit and at rest
  5. What we deliberately do not hold
  6. Reporting a vulnerability
  7. If something goes wrong

Separation between companies

Every record belongs to exactly one company workspace, and that ownership is enforced in the database itself rather than by the screens on top of it. A request that asks for another company’s data does not get it, however it is made.

Accounts and access

  • Sign-in is handled by a dedicated authentication provider. We never see or store your password.
  • Inside a company there are two levels: an admin who sets the buyer profile and manages the team, and employees who work inside it.
  • An account can be archived immediately, which ends access while leaving the work it created intact.

Mailbox credentials

If you connect a mailbox, its password is encrypted with a key held outside the database, and it is never displayed back to anyone - not to you, and not to us. A leaked copy of the database on its own would not let anybody send mail as you.

In transit and at rest

Traffic to the service is encrypted in transit. Data at rest sits with our database and hosting providers, encrypted under their platform controls and backed up on their schedule.

What we deliberately do not hold

  • Card numbers - payments are not taken on this site.
  • Passwords in readable form, for your account or for a connected mailbox.
  • Personal data about the contacts our customers reach, beyond published workplace details.

Reporting a vulnerability

Write to security@samoraone.com with enough detail to reproduce it. We will confirm receipt, keep you updated while we fix it, and credit you if you would like that.

Please do not run automated scans against the live service, do not access or alter data that is not yours, and give us a reasonable chance to fix the issue before publishing it. Report in good faith and we will not pursue you for it.

If something goes wrong

If a breach affects your data we will tell you what happened, what it touched and what we are doing about it, without waiting until the story is tidy. Where the law requires us to notify a regulator, we will.