Skip to main content
Security and privacy

Your data, properly looked after

Encryption, access control, backups and an audit trail of every action — in the product from day one, not sold as an add-on.

Data encryption
Secure connection (HTTPS)
Role-based access
GDPR compliant
Regular backups
Audit log

Protection at every level

Security is built into the product — from how data is stored to what each person can see on screen.

Encryption and protection

  • Confidential data is stored encrypted
  • The connection to the app is secured (HTTPS)
  • Integration tokens never leave the server in the clear
  • Passwords are stored only in hashed form — nobody at Pipevale can read yours

Access control

  • Built-in roles: Owner / Admin / Manager / Viewer
  • Custom roles with your own permission set
  • Folder-level access restrictions
  • Individual fields can be hidden or made read-only

Audit log

  • Every create, change and delete is recorded
  • You see who changed what, and when
  • Filters by event type, user and date
  • Available to administrators in settings

Two-factor authentication

  • TOTP apps — Google Authenticator, Authy, 1Password
  • QR code for quick setup
  • Recovery codes in case you lose the device
  • Each user enables it for their own account

Single sign-on (SSO)

  • SAML 2.0 — Google Workspace, Microsoft Entra, Okta and others
  • Sign in with the corporate account, no separate password
  • Users provisioned on first sign-in
  • Sign-in can be restricted to your company's email domain

Backups

  • The database is backed up regularly and automatically
  • Protection against technical failure
  • Your data survives events outside your control

Tenant isolation

  • Each customer's data is strictly isolated from every other
  • Reaching another customer's data is not technically possible
  • A single controlled path to data, not scattered queries
GDPR

Built to meet GDPR

Pipevale processes personal data in line with the EU General Data Protection Regulation. For the data you put into your workspace you are the controller and we are the processor — the details are in our Data Processing Agreement.

  • Data is stored within the EU
  • Right to receive a copy of all workspace data
  • Full deletion on request from an administrator
  • We process only the data the service needs to work
  • We never sell or hand your data to third parties
  • Opt in and out of marketing email
Data stays in the EU
European data residency

Your CRM database is hosted inside the European Union. You can take a copy of your data or delete it at any time.

To request a copy of your data or delete it, go to Settings → Data and privacy inside your Pipevale account.

Security questions

How is my data protected?

Confidential data and integration tokens are stored encrypted, the connection to the app is secured with HTTPS, and access to data is controlled by roles. Each customer's data is strictly isolated from every other customer's.

How are passwords stored?

Passwords are never stored in readable form — only hashed. Nobody at Pipevale, including the team, can see your password.

Can I turn on two-factor authentication?

Yes. Pipevale supports TOTP — Google Authenticator, Authy, 1Password and others. Each user enables 2FA in their own security settings and receives recovery codes in case the device is lost.

Are integration tokens protected?

Yes. Tokens and keys for external services are stored encrypted and are never sent to the browser in the clear.

Is Pipevale GDPR compliant?

Yes. We process personal data in line with GDPR, store data within the EU, and provide tools for full export and deletion of workspace data on an administrator's request. Our processor obligations are set out in the Data Processing Agreement.

Are there backups?

Yes. The database is backed up regularly and automatically, so your data is safe even if something fails technically.

Can I see a log of what happened in the system?

Yes. Every change in the CRM is written to an audit log. Administrators can browse and filter it under Settings → Audit log.

Responsible disclosure

Vulnerability disclosure policy

We are grateful to the security researchers who help make Pipevale safer. If you find a vulnerability, tell us and we will act on it.

Scope

Pipevale’s public services: the site pipevale.com, the application, and operator.pipevale.com.

How to report

Write to security@pipevale.com. Please include what the problem is, where you found it (URL or section), the impact you expect and how to reproduce it — a proof of concept if you have one. That lets us verify it quickly.

Safe harbour

Research carried out in good faith and in line with this policy is considered authorised, and we will not pursue legal claims over it. Please give us reasonable time to fix the issue before making it public.

What not to do

  • denial of service (DoS/DDoS) or load testing;
  • social engineering, phishing or physical intrusion;
  • accessing, changing or deleting other users’ data — use your own test accounts;
  • anything that degrades the service for other people.

What we commit to

We acknowledge reports within 3 working days, keep you informed, fix confirmed vulnerabilities within a reasonable time and — if you want it — credit you.

Questions about security?

The Pipevale team answers questions about security and data processing directly.

We reply within one working day.