Skip to main content
Security & Integrations

Security and integrations, for technical teams

How CloseUp is built, secured and connected. For CTOs, IT managers, RevOps and integrators.

Architecture at a glance

  • Managed multi-tenant SaaS, operated by the CloseUp team.
  • Every record carries a company ID. Tenant isolation is enforced in the application and checked automatically on every build, with PostgreSQL row-level security as an extra layer on core tables.
  • PostgreSQL database with versioned migrations.
  • Background job queue with retries and dead-letter handling for AI analysis, transcription, mail and ad sync, conversion uploads and outreach.
  • Real-time UI updates over Server-Sent Events (SSE).
  • All writes go through authenticated server-side actions. The browser never talks to the database.

Access control

  • Role-based permissions with 13 built-in roles, plus team-based lead visibility: own, team, sub-tree or company. Unknown scopes are denied.
  • The viewer role is read-only, enforced on the server.
  • Two-factor authentication (TOTP) with backup codes, enforceable company-wide.
  • 30-minute idle and 12-hour absolute session timeouts, with server-side session revocation.
  • Passwords hashed with bcrypt, a password policy, and login lockout after repeated failures.
  • Audit log of logins, data access and admin actions, kept for 24 months.

Data protection

  • Integration secrets encrypted at rest with AES-256-GCM, with a key-rotation procedure.
  • Inbound webhooks verify the sender: provider HMAC signatures (such as Meta and Twilio), per-tenant signed tokens or per-key HMAC.
  • Content Security Policy, HSTS and anti-framing headers.
  • Automated security scanning in CI (CodeQL, Semgrep, OWASP ZAP), plus an automated test suite.

Privacy and data control

  • Company data export (JSON) on request or at termination.
  • Company erasure with a 30-day grace period, then deletion of records, uploads and AI logs, with deletion receipts.
  • Deleted leads can be restored for 30 days; after that, derived data is permanently erased.
  • Automatic retention windows, for example 90 days for integration logs and AI input/output, and 24 months for security logs.
  • Per-company switches to turn off AI processing and call transcription.
  • Marketing consent per lead and one-click unsubscribe for bulk messaging.
  • Sub-processors: OpenAI, Google, Deepgram, Meta, Green API, Twilio.

Integration model

  • Three configuration levels: platform (CloseUp team), company (admins with the manage-integrations permission) and user (each rep).
  • Each rep connects their own calendar, mailbox and Zoom with OAuth.
  • Ad accounts are connected and selected by the CloseUp team; company admins can trigger a re-sync.

API and webhooks

  • A focused REST API (Business plan and above) for lead status sync and appointments. Lead intake goes through webhooks, not this API.
  • Company API key (X-API-Key or Bearer), optional HMAC-SHA256 request signing, 120 requests per minute per key, idempotency keys and request IDs.
  • Lead intake webhooks with per-campaign tokens and ready-made code snippets in 7 programming languages.
  • MCP server for AI assistants (early access): OAuth 2.1 + PKCE, scoped to the user's own permissions.

Questions for your security review?

Talk to our team and we'll walk you through the details.
Talk to an integration expert