Integration

What actually protects your data here.

Security pages love vague reassurance. This one lists mechanisms: what is enforced, where, and by what.

Workspace isolation at the database

Every table carries a workspace ID and row-level security enforces it on every query. A deactivated member loses access at the database layer, not just the UI.

OAuth tokens encrypted at rest

Calendar and integration tokens are stored AES-256-GCM encrypted. The database never holds a plaintext token.

Workspace security controls

Admins set session length limits, require MFA, and restrict by IP — enforced by middleware on every request, not a settings page for show.

Cards never touch our servers

Payments run through Stripe Checkout on your own Stripe account. Card numbers go to Stripe; we store the booking, not the card.

Your data leaves when you ask

Full export on request, and public booking actions run on scoped tokens — cancel and reschedule links work without an account and expose only that booking.
What we do not claim: no SOC 2 or HIPAA certification today. If your compliance bar requires them, email chase@tnvex.com and ask where things stand before you commit.

Related

Questions a page can’t answer? Ask a person.

Free forever plan. No credit card.