Security

Built to keep your customers' information safe.

Saphen handles your leads' names, contact details and conversations. Here's how we protect them.

Data separated per business

Every record belongs to one business, and the database itself refuses to show one business's data to another (row-level security), not just the app.

Encryption

All traffic uses HTTPS. Data is encrypted at rest by our database provider. Google Calendar connection tokens are additionally encrypted by Saphen before they're stored.

Least-privilege calendar access

Saphen asks Google only for permission to see when you're busy (never your event details) and to manage the events it books.

Verified connections

Messages from Stripe and our email and texting providers are checked for a valid signature before Saphen acts on them.

Roles

Owners, staff and view-only users. Only the account owner can change billing.

Human review

The Saphen team reviews every new business before it can message anyone, and can pause any business immediately.

Where your data lives

Saphen runs on established providers, each used for one job. They process data on our behalf under their own security programs.

ProviderUsed for
VercelHosting the Saphen app and this website
SupabaseDatabase and sign-in
AnthropicAI that drafts messages and understands replies
ResendSending and receiving email
TwilioSending and receiving text messages
StripePayments and billing
GoogleCalendar (only if you connect it)

What Saphen is not for

Saphen is not designed for protected health information and is not HIPAA compliant. Please don't use it to collect medical details, payment card numbers or government ID numbers from your customers.

Report a security issue

If you believe you've found a vulnerability, email hello@saphen.ai with “Security” in the subject. Please give us a reasonable chance to fix it before telling anyone else. See also our privacy policy.