Security
Your data is protected at every layer.
We take your clients' and projects' data as seriously as you do. Here's how Encorv's security is actually built — no buzzwords, just what's really there.
Encryption in transit
Every request to Encorv travels over HTTPS/TLS. Data is never sent in the clear.
Isolation between organizations
Every data query is scoped at the workspace level — one organization has no way to see another's data.
Short-lived tokens
Logging in issues a short-lived access token and a separate refresh token. The refresh token rotates on every use, and the previous one is revoked, not just discarded.
Roles and permissions
Four roles — owner, admin, manager, member — each with a defined set of permissions across companies, contacts, projects, tasks, files and quotes.
Audit trail
Changes to any record — a company, contact, project or task — are logged: what changed, when, and who did it.
Email-based invitations
New team members only join a workspace via an email invitation with a role already assigned — never an open link.
Infrastructure
The app and database run on managed cloud infrastructure (Railway) — no self-administered servers on our end.
Have a security question?
Write to our team — we'll answer technical and compliance questions directly.