Security

Your data is protected at every layer.

We take your clients' and projects' data as seriously as you do. Here's how Encorv's security is actually built — no buzzwords, just what's really there.

Encryption in transit

Every request to Encorv travels over HTTPS/TLS. Data is never sent in the clear.

Isolation between organizations

Every data query is scoped at the workspace level — one organization has no way to see another's data.

Short-lived tokens

Logging in issues a short-lived access token and a separate refresh token. The refresh token rotates on every use, and the previous one is revoked, not just discarded.

Roles and permissions

Four roles — owner, admin, manager, member — each with a defined set of permissions across companies, contacts, projects, tasks, files and quotes.

Audit trail

Changes to any record — a company, contact, project or task — are logged: what changed, when, and who did it.

Email-based invitations

New team members only join a workspace via an email invitation with a role already assigned — never an open link.

Infrastructure

The app and database run on managed cloud infrastructure (Railway) — no self-administered servers on our end.

Have a security question?

Write to our team — we'll answer technical and compliance questions directly.