SECURITY
Lettrove is built for teams that answer to auditors. Access control, an audit trail, and reviewed change management are wired in from the ground up — and our architecture is designed to make SOC 2 accreditation straightforward.
Owner, admin, editor and viewer roles, enforced deny-by-default on every action. Permission checks read live membership, so revoking access takes effect immediately.
TLS everywhere. Passwords are hashed with scrypt; session, verification and invitation tokens are stored hashed, single-use and expiring.
Every privileged action — invites, role changes, removals, sends — is recorded to an append-only log your admins can review on the Activity page.
Your users, credentials and org membership live in our own database — not a third-party identity vendor — keeping our subprocessor list short.
New teammates start with only what their role needs. Admins control who can invite, change roles, and send campaigns.
Every database change ships as a reviewed, committed migration. Quality gates run on each change before it reaches production.
Our controls map to the Trust Services Criteria, and our change history is our evidence. Talk to us about your compliance requirements.
Create your account →