Keepstone stores copies of your CRM data, so security is foundational.
OAuth 2.0 authorization-code flow only — no token copy/paste. We request least-privilege scopes (read for backup; write only for restores you initiate). Each portal's data is isolated by portal ID.
Backups are AES-256 encrypted at rest and transmitted over TLS 1.2/1.3. OAuth tokens are envelope-encrypted with a key held outside our codebase, rotated, and revoked on uninstall. Incoming HubSpot webhooks are signature-verified.
Backend services run non-root and bound to localhost behind a TLS reverse proxy. We keep an immutable audit log of every backup, restore, export and settings action.
Your data is used only to provide the service, never sold or shared. Retention follows your plan; on uninstall we offer an export window and then delete. See our Privacy Policy.
Report security concerns to connect@sgbp.tech.