Security
Last updated:
How Surge Service protects your data and your customers' data, and how to report a vulnerability.
Draft for legal review
Surge Service holds your customer conversations and a mirror of your Pipedrive data. This page explains how we protect them. The binding version of these measures is annex 2 of our Data Processing Agreement.
1.Separation between customers
- Every record that holds your data carries your company identifier. The database enforces row-level security on every such table, so a query can only return rows of the company it runs for. This is enforced by the database itself, not only by application code.
- We identify your company only from a verified source: your signed session, a signed token issued by Pipedrive, or webhook credentials unique to your company. Never from a value in a web address or form.
2.Encryption
- All traffic to and from the app is encrypted with TLS.
- Pipedrive access tokens, refresh tokens and webhook credentials are encrypted with AES-GCM before we store them. The encryption key is kept separately from the database.
- Stored data is encrypted at rest by our hosting and database providers. Open point: [confirm encryption at rest with the providers]
3.Access to your Pipedrive account
- The app asks only for the Pipedrive permissions its features need. You see and approve them during installation.
- The app acts in Pipedrive only for what you configure, such as creating activities for tickets and playbooks, or leads and deals from support signals.
- When you uninstall the app, we immediately delete the stored tokens and remove our webhooks.
4.Who can see what
- Users sign in with their Pipedrive account. Roles decide what they can do: admins change settings, agents work tickets and viewers read.
- Sessions use signed cookies with HttpOnly, Secure and SameSite=Lax that expire after 7 days without use.
- The views inside Pipedrive use a short-lived token that lives only in memory, never in cookies or browser storage.
- Only named Sales Surge staff who need it for their work can access production systems, under confidentiality obligations.
5.Email and message content
- Incoming HTML is cleaned against an allowlist before it is stored, so scripts and unsafe markup never reach your agents' screens.
- Outgoing email is built only from our own templates.
- Every input is validated: web requests, webhooks and inbound email. Every public endpoint is rate limited.
- Our logs never contain tokens, secrets, email bodies or personal data beyond identifiers.
6.AI features
AI features stay off until an admin switches them on. When they are on, only the content needed for a request is sent to our AI provider, whose commercial terms do not allow training models on customer content. A person always reviews and sends a reply. See Sub-processors.
7.Hosting and resilience
- Your data is stored in the European Economic Area. Open point: [confirm hosting and database regions]
- Incoming email and Pipedrive updates are saved before processing and handled by a queue that retries, so a short outage does not lose messages. Duplicates are recognised and ignored.
- We make regular backups. Open point: [confirm backup frequency, retention and restore testing]
- Test and load traffic never touches real customer accounts.
8.Incidents
If a security incident affects your personal data, we notify your admins without undue delay, as set out in the Data Processing Agreement. We tell you what happened, what it means for you and what we are doing about it.
9.Responsible disclosure
Found a vulnerability? Please email info@sales-surge.nl with "Security" in the subject line. Describe the issue, the steps to reproduce it and the impact you expect. Open point: [consider a dedicated security mailbox and a security.txt file]
What we ask of you
- Only use your own account or a test account. Do not access, change or delete data of others beyond what is needed to show the issue.
- No denial-of-service testing, social engineering, spam or physical attacks.
- Give us reasonable time to fix the issue before you share it with others. We aim for 90 days.
- Report issues in Pipedrive itself to Pipedrive, and issues in third-party services to their owners.
What you can expect from us
- We confirm receipt within Open point: [acknowledgement time, for example 3 business days; to confirm] and keep you informed about the fix.
- We will not take legal action against research carried out in good faith within these rules.
- With your permission, we credit you once the issue is fixed. We do not run a paid bug bounty programme.