Skip to content

Clear boundaries around your business.

Read how Evarmont handles organization access, integration credentials, sensitive call data and retention. Concrete controls without certification claims.

Access follows the organization

The API resolves active membership and permissions on the server. Organization-scoped repository operations carry an explicit organization identifier. Database row-level policies provide another boundary around tenant data.

A hidden button is not authorization. Cross-organization resource lookups are refused, and restricted roles do not receive fields they are not permitted to view.

Provider credentials stay server-side

OAuth connections use the provider’s consent flow. Integration grants are encrypted in a private credential store and bound to the organization and connection. Browser responses contain connection state and permitted operations, not provider secrets.

Stripe Connect uses hosted account onboarding rather than the OAuth path. Disconnect and health-check behavior differs by provider; the integration pages explain those differences.

Sensitive records have narrower access

Transcripts and recording access are subject to role and retention checks. Retention workers remove expired transcript content and handle customer-data erasure according to configured policy.

Operational logs use identifiers, outcome codes and timing rather than raw transcripts, provider payloads or credential values. The HubSpot activity adapter uses a short summary and a dashboard link instead of exporting full transcripts.

Actions are validated at the boundary

Provider callbacks are authenticated with the mechanism supported by that provider and deduplicated. Booking changes require authorization and idempotency protection. Customer booking-management credentials have a separate verification path.

The public website uses local media, escaped content and no added advertising or analytics scripts. Account and booking routes retain their own server-side access rules.

Questions about your requirements

This page describes implemented controls. It does not assert certification, a compliance status or an external audit. Review your data requirements and provider arrangements before connecting a live business line.

For privacy questions, use the contact published in our Privacy Policy. A dedicated vulnerability-reporting contact has not yet been published; do not send sensitive exploit details through the demo form.

Discuss your workflow

Start with one everyday call.

See where it can lead, and what your team can review afterward.

Explore a demo