SECURITY CENTER

CONTROL THE DATA.
PRESERVE THE DECISION.

A precise view of DRIFTMIRROR's current access, data, authority and privacy boundaries for customer onboarding.

SOURCE CRMREAD-ONLY ADAPTERMINIMAL DEAL MODELMECHANICS / RULES / TESTS

CRM ACCESS MODEL

CURRENT MODEL

HubSpot is connected read-only. DRIFTMIRROR does not automatically write stages, owners, amounts, close dates, next steps, activities, contacts or companies back into the CRM.

DATA MINIMIZATION

CURRENT MODEL

DRIFTMIRROR uses the source evidence required to reconstruct comparable deal episodes. Call transcripts, email bodies and unrestricted CRM field access are not required.

EMPLOYEE PRIVACY / NO REP SCORING

CURRENT MODEL

The structural unit is the recurring mechanic. DRIFTMIRROR does not create employee scores or psychological profiles.

ACCESS & AUTHORITY MODEL

CURRENT MODEL

Workspace access and operating authority are separate. Membership and role checks govern who may review, propose, approve or administer changes.

CREDENTIAL PROTECTION

CURRENT MODEL

HubSpot OAuth credentials remain server-side. Stored OAuth credentials are encrypted with AES-GCM and are not returned to the browser.

TENANT ISOLATION

CURRENT MODEL

Workspace-scoped access controls and row-level security keep customer data inside the authorized workspace boundary.

AUDITABILITY

CURRENT MODEL

Security and administrative audit records are kept separate from Operating Memory so product history and administrative accountability remain distinct.

RETENTION & DELETION

CURRENT MODEL

Workspace export and deletion paths are built into the product. Contractual retention periods are defined for the production relationship rather than invented on this page.

BACKUP & RECOVERY

CURRENT MODEL

DRIFTMIRROR maintains a documented backup and restore procedure. Production restore evidence is verified against the deployed environment before customer onboarding.

INCIDENT HANDLING

CURRENT MODEL

The production operating model requires defined incident ownership, containment, evidence preservation, credential rotation where needed, remediation and customer/legal notification as applicable.

AI / MODEL DATA BOUNDARY

CURRENT MODEL

Server-side model calls are limited to candidate-generation and planning functions using explicitly constructed structural context. HubSpot OAuth tokens, call transcripts and email bodies are not part of that model input.

SUBPROCESSORS

CURRENT MODEL

Production data recipients are documented before use. The current architecture uses Supabase for core platform services and OpenAI API for limited server-side candidate/planning processing.

Provider-specific production facts such as deployment region, retention periods, backup configuration and completed restore evidence are verified for the deployed customer environment and are not replaced by generic marketing claims.