Security

Your mailbox is not our product

Attendlee asks for real trust — calendar access and permission to send as your reps. We hold that trust the same way we’d want ours held: least privilege, plain answers, one-click revocation.

Least privilege, always

Scoped Microsoft Graph and HubSpot OAuth. Each rep consents individually. We request the narrowest scopes that make the product work — and list every one below.

We don’t read your email

Attendlee watches invite responses, not inboxes. No body scanning, no contact mining, no “relationship intelligence.” Nudges are written by templates you approve.

Leave cleanly, anytime

Revoke tenant or per-rep access in one click — from our admin panel or yours. Full data export on request; deletion within 30 days, confirmed in writing.

Data handling

What we store, in one screen

Short enough to actually read. If your security team wants the long version, we’ll walk them through it live.

We store
We never store
Meeting metadata — title, time, organizer, invitees
Response states and nudge history
Engagement signals — delivered, opened, page viewed, confirmed
OAuth tokens, encrypted per-tenant
Email bodies or attachments
Passwords — OAuth only, ever
Meeting recordings or transcripts
Anything about non-invitees

The practices behind that

Working toward SOC 2
Controls are being built to SOC 2 Type II standards from day one. A formal audit is planned; current controls documentation is available on request.
Encryption everywhere
TLS 1.2+ in transit, AES-256 at rest, tokens encrypted with per-tenant keys in a managed KMS.
Tenant isolation
Your workspace’s data is partitioned per tenant; no cross-customer queries, no shared caches of your calendar data.
Engagement telemetry, first-party only
Delivery, opens, and confirmation-page engagement are measured so reps can read the room — and it stays between you and Attendlee. No ad networks, no third-party pixels, nothing sold or shared.
Access-reviewed, logged, small
Production access is limited to a small set of engineers, audit-logged, and reviewed monthly. SSO + hardware keys internally.
Subprocessors, listed
A short, published list — cloud hosting and email delivery. We’ll notify you 30 days before adding one.

Put your security team on a call with ours

Questionnaires answered within a week. Architecture walkthroughs gladly.

security@attendlee.com