Skip to content
Falconzo home

Security

Sensible protection, described honestly

Falconzo holds your customer relationships and, if you connect a mailbox, your conversations. This page sets out what we actually do to protect that, and is equally clear about what we do not claim.

How your data is protected

What we do

Six protections that are built into the product rather than promised in a brochure.

  • Passwords are hashed

    Passwords are stored as a bcrypt hash, never in readable form. Nobody at Falconzo can look up or recover your password.

  • Mailbox credentials are encrypted

    The OAuth tokens and IMAP passwords that keep a mailbox syncing are encrypted with AES-256-GCM before they are stored.

  • Credentials never reach the browser

    Those credentials stay on the server and are used only to talk to your provider. They are never sent to the page you are looking at.

  • Mail is sanitised before display

    Scripts, embedded styles and event handlers are stripped out of a message before it is rendered, so opening mail cannot run code in Falconzo.

  • Remote images are blocked by default

    A remote image can tell the sender that you opened a message. Falconzo blocks them until you decide to load them, per message.

  • Personal mailboxes stay personal

    A mailbox you connect is visible only to you. Colleagues and administrators do not see its contents in Falconzo.

Access

Who can see what

Most data incidents inside a business are not attacks. They are the wrong person seeing something they should not.

  • Roles and permissions

    Each person gets a role that decides what they can see and do. Shared mailboxes and shared inboxes follow the same rules as records.

  • Audit log and field history

    Every change to a record is recorded, and each field keeps its history: the old value, the new value, who changed it and when.

  • Connections you control

    You authorise a mailbox or a messaging channel on the authorisation screen the provider itself shows you, and you can disconnect it from settings at any time, which deletes the stored credentials.

Each organisation's data is kept separate from every other organisation's. Inside an organisation, roles decide what a person can reach.

Mailboxes work the same way, with one addition worth stating plainly. A mailbox you connect starts as personal, and personal means only you can read it in Falconzo. If your team needs a shared address such as sales or support, someone with the right permission converts that connection into a shared mailbox, and from then on it is governed by permissions like everything else. The change is deliberate and visible, not something that happens quietly.

Attachments on mail stay with your mail provider. Falconzo lists what is attached and fetches a file from the provider when somebody asks to download it.

Reading mail safely

Why mail gets special treatment

An inbox is the one place in a business tool where untrusted content arrives every day.

Email is written by people you have not met, and an HTML message can carry things you would never allow in your own application. Falconzo cleans every message before it is shown. Scripts, embedded style blocks and event handlers are removed, so a message cannot run code or reshape the page around it.

Remote images are blocked until you choose to load them. This is not fussiness. An image loaded from the sender's server tells the sender that the message was opened, roughly when, and from where. Falconzo shows you that a message contains remote images and leaves the decision with you.

When you send, Falconzo refuses to email a contact or lead who is marked as opted out. That is a backstop for your own process, not a replacement for it.

Being straight with you

What we do not claim

A security page that claims everything tells you nothing. Here is what is not on offer today.

  • We do not hold SOC 2, ISO 27001 or any other security certification, and we do not describe Falconzo as certified or as compliant with a named regime.
  • We do not publish an uptime figure, a response time or a service level agreement on this page. If your contract includes commitments, they are in that agreement rather than here.
  • We do not offer data residency options or promise a hosting location on this page.
  • We do not claim independent penetration testing, a bug bounty programme or a third-party audit.
  • We do not state backup schedules or deletion timelines here. Export your data regularly if it matters to you, which you can do at any time.

If your procurement process needs a written answer on any of these, ask us. A specific answer under an agreement is worth more than a badge on a marketing page.

Reporting

Found a problem? Tell us

We would rather hear about a weakness from you than read about it later.

Send security reports to [Privacy contact email]. Include what you found, how to reproduce it, and what you think the impact is. Please give us a reasonable chance to fix an issue before you publish it, and please do not access, change or delete anybody else's data while investigating.

For what we collect and how long we keep it, see the privacy policy and the data deletion page. For anything else, the contact page reaches us.

Questions before you move your customer data

Bring your security checklist to a call and we will answer it directly, including the parts where the answer is no.