Security practices

Security designed around access boundaries and prepared reporting snapshots.

This page describes implementation details verified in the current product architecture. It does not claim certifications, guarantees, or independent assessments that have not been completed.

Authentication and access control

Clerk provides authentication and organization context. The application verifies sessions and limits access by organization and role.

Tenant separation

Account sources, assignments, and access checks are organization-scoped. Dashboard assignments belong to a connected HighLevel location.

Credential protection

PIT and OAuth credentials are encrypted by the application before D1 storage and are not returned to browser clients.

Snapshot architecture

Public embeds read cached D1 dashboard snapshots. They never call HighLevel directly from the iframe.

Retention and drilldowns

Aggregate reporting is retained for the dashboard. Recent capped drilldown data and pagination state are encrypted; older history is bounded to aggregate data.

Revocation and deletion

Authorized source managers can disconnect an account, invalidating the embed and clearing the associated source data.

Responsible disclosure

Security reporting contact details are not published until an active, monitored intake is approved. Do not submit credentials, tokens, embed keys, passwords, or customer exports through website forms. See the launch checklist for the security-contact requirement.

Data usageSubprocessors

Ready when your next client is

Give reporting a clear, repeatable home.

Start with one connected account, explore the templates, or tell us how you deliver client reporting today.