Integration
What actually protects your data here.
Security pages love vague reassurance. This one lists mechanisms: what is enforced, where, and by what.
Workspace isolation at the database
Every table carries a workspace ID and row-level security enforces it on every query. A deactivated member loses access at the database layer, not just the UI.
OAuth tokens encrypted at rest
Calendar and integration tokens are stored AES-256-GCM encrypted. The database never holds a plaintext token.
Workspace security controls
Admins set session length limits, require MFA, and restrict by IP — enforced by middleware on every request, not a settings page for show.
Cards never touch our servers
Payments run through Stripe Checkout on your own Stripe account. Card numbers go to Stripe; we store the booking, not the card.
Your data leaves when you ask
Full export on request, and public booking actions run on scoped tokens — cancel and reschedule links work without an account and expose only that booking.
What we do not claim: no SOC 2 or HIPAA certification today. If your compliance bar requires them, email chase@tnvex.com and ask where things stand before you commit.
Related
Questions a page can’t answer? Ask a person.
Free forever plan. No credit card.