Security isn’t a feature we bolted on.
SeamMagnet holds your team’s pipeline, your outreach copy, and the credentials that connect your mailbox, LinkedIn account, and calendar. That’s sensitive by default, so it’s treated that way in how the product is built — not as a checklist added at the end. Here’s exactly what that means, in plain terms.
How it works
What protects your data
Four places security decisions actually show up in the product.
Payments
Stripe handles all card data directly. When you subscribe or add seats, your card details go straight to Stripe — SeamMagnet's own servers never store or even see a full card number.
Encryption
Every credential we store on your behalf — mailbox passwords, LinkedIn session tokens, calendar refresh tokens, webhook signing secrets, provider API keys — is AES-256-GCM encrypted at rest, not just at the database layer.
Access & isolation
Access inside your org is role-based: Owner, Admin, Manager, and Member each see and do only what their role allows. Every organization's leads, campaigns, and settings are scoped to that organization — there's no cross-org visibility.
Infrastructure
Every connection to SeamMagnet runs over HTTPS. The API sits behind rate limiting and an origin allowlist. All database access goes through stored procedures — never inline SQL — which closes off the most common injection surface by design.
Responsible disclosure
If you’re a security researcher and you find a vulnerability in SeamMagnet, we want to hear about it before anyone else does. Email [email protected] with what you found and how to reproduce it. We’ll follow up directly — no bounty program to advertise, just a real inbox that gets read.