Security & Integrations
Security and integrations, for technical teams
How CloseUp is built, secured and connected. For CTOs, IT managers, RevOps and integrators.
Architecture at a glance
- Managed multi-tenant SaaS, operated by the CloseUp team.
- Every record carries a company ID. Tenant isolation is enforced in the application and checked automatically on every build, with PostgreSQL row-level security as an extra layer on core tables.
- PostgreSQL database with versioned migrations.
- Background job queue with retries and dead-letter handling for AI analysis, transcription, mail and ad sync, conversion uploads and outreach.
- Real-time UI updates over Server-Sent Events (SSE).
- All writes go through authenticated server-side actions. The browser never talks to the database.
Access control
- Role-based permissions with 13 built-in roles, plus team-based lead visibility: own, team, sub-tree or company. Unknown scopes are denied.
- The viewer role is read-only, enforced on the server.
- Two-factor authentication (TOTP) with backup codes, enforceable company-wide.
- 30-minute idle and 12-hour absolute session timeouts, with server-side session revocation.
- Passwords hashed with bcrypt, a password policy, and login lockout after repeated failures.
- Audit log of logins, data access and admin actions, kept for 24 months.
Data protection
- Integration secrets encrypted at rest with AES-256-GCM, with a key-rotation procedure.
- Inbound webhooks verify the sender: provider HMAC signatures (such as Meta and Twilio), per-tenant signed tokens or per-key HMAC.
- Content Security Policy, HSTS and anti-framing headers.
- Automated security scanning in CI (CodeQL, Semgrep, OWASP ZAP), plus an automated test suite.
Privacy and data control
- Company data export (JSON) on request or at termination.
- Company erasure with a 30-day grace period, then deletion of records, uploads and AI logs, with deletion receipts.
- Deleted leads can be restored for 30 days; after that, derived data is permanently erased.
- Automatic retention windows, for example 90 days for integration logs and AI input/output, and 24 months for security logs.
- Per-company switches to turn off AI processing and call transcription.
- Marketing consent per lead and one-click unsubscribe for bulk messaging.
- Sub-processors: OpenAI, Google, Deepgram, Meta, Green API, Twilio.
Integration model
- Three configuration levels: platform (CloseUp team), company (admins with the manage-integrations permission) and user (each rep).
- Each rep connects their own calendar, mailbox and Zoom with OAuth.
- Ad accounts are connected and selected by the CloseUp team; company admins can trigger a re-sync.
API and webhooks
- A focused REST API (Business plan and above) for lead status sync and appointments. Lead intake goes through webhooks, not this API.
- Company API key (X-API-Key or Bearer), optional HMAC-SHA256 request signing, 120 requests per minute per key, idempotency keys and request IDs.
- Lead intake webhooks with per-campaign tokens and ready-made code snippets in 7 programming languages.
- MCP server for AI assistants (early access): OAuth 2.1 + PKCE, scoped to the user's own permissions.
Questions for your security review?
Talk to our team and we'll walk you through the details.
Talk to an integration expert