Security
Built to be trusted with your data.
Isolated workspace data, encrypted credentials, and human approval on every action that leaves the app.
Workspace data isolation
Every record is scoped to your organization. A query from one company cannot reach another company's data — the boundary is enforced at every call site, not just at the login screen.
Encrypted credentials
OAuth tokens for every connected system — CRM, ERP, email, Slack — are encrypted at rest, never stored in plain text.
Read-only by default
Overstacx starts read-only against your CRM and ERP. Nothing is created or changed in your systems of record unless you explicitly connect a send integration — and even then, a human approves every action.
A human approves every send
Email and Slack sends require a real person to read the exact drafted text and click send. Nothing goes out automatically.
Standard OAuth, nothing custom
Every connection uses each provider's own authorization flow — Salesforce, HubSpot, NetSuite, QuickBooks, Google, Microsoft, Slack. We never ask for a password directly.
Disconnect anytime
Revoke access from Overstacx or from the provider's own settings at any time. Nothing is retained that requires ongoing access to delete.
Questions about your specific security review or a questionnaire you need filled out? Talk to us directly — we’re happy to walk through the details.
Connect your CRM and ERP. See what’s actually reconciled in the first week.
No contract to start. Read-only access. We’ll walk your data with you before you decide anything.
Talk to us