Trust basics

Security
at a glance.

Access and data first. Payments last. This page separates controls that are in place today, ones that depend on how your workspace is configured, and items still on the roadmap. It is not a compliance certification.

Verified today

01

Access — magic-link sign-in

Workspace owners sign in with a one-time email link. Sessions expire. There is no open public signup; access is granted for your workspace.

02

Data — proof trail

Meaningful actions can carry sealed receipts — message, tracker, or system ids — so finished steps are inspectable. Work packets carry ownership; policy capsules pin versions.

How receipts work →

03

This website

Static marketing pages. No application secrets in client assets. Security headers via site configuration (nosniff, frame denial, referrer policy).

Depends on configuration

01

Tenant isolation

Customer, team, and environment boundaries are designed to stay scoped with tenant-aware routing. Exact isolation strength depends on how your workspace and connectors are provisioned.

02

Integrations

Connectors are intended to be least-privilege for the systems you attach. Credentials are not embedded in this marketing site; live connector scope is set during workspace setup.

Coming later

01

Formal questionnaires & certifications

Security questionnaires, DPA language, and certifications will be published separately when available. For vendor review, email [email protected].

Payments

01

Paddle as Merchant of Record

Token purchases are processed by Paddle. Card data and tax handling sit with Paddle’s checkout — not on Wakehold’s public site. Packs and Live prices are configured on Pricing; if self-serve checkout isn’t available yet when you click Buy, email [email protected]. Same checkout story as Pricing and How it works.