Skip to content

Exclusive 50% off for 36 months for the first 100 Professional accounts, until 31 December 2026. See the programme →

Security & compliance · Encryption

Nothing travels or sits in the clear

Every exchange between your browser, our services and our partners is encrypted. Every stored piece of data — databases, files, backups — is encrypted too. Passwords are hashed, and secrets live neither in the code nor in a shared file.

No credit card required

In practice

Three layers, no exceptions

In transit: HTTPS everywhere

The browser talks to the platform over HTTPS, and the platform talks to itself encrypted: exchanges between services, message queues and database connections all go through encrypted channels. Obsolete TLS versions are refused.

  • HTTPS required on the application, the portal and the API
  • Obsolete TLS versions refused
  • Encrypted inter-service exchanges and message queues
  • Encrypted database connections

At rest: databases, files, backups

Database volumes, document storage and backups are encrypted at rest by the infrastructure provider. Passwords are never stored: only a fingerprint, computed with a slow, salted algorithm, is.

  • Encryption at rest for databases and file storage
  • Encrypted backups
  • Passwords hashed with a slow, salted algorithm
  • Revocable API keys, usage monitored (new IP address detected)

Secrets are managed on their own

API keys, certificates, third-party service credentials: none of them are in the source code or in a shared configuration file. They are injected into the services by the hosting platform, service by service, and replaced on demand.

  • No secrets in the source code
  • Injection by the hosting platform, service by service
  • Keys and certificates replaced on demand
  • Technical access restricted and reviewed
On request

What you can demand from us

The technical details your CISO needs, provided on request.

  • Encryption policy (in transit, at rest, secrets)
  • Description of secret management and technical access
  • Password and API key policy
  • Register of subprocessors with locations
dpo@metaventus.com

FAQ

Frequently asked questions

Can your teams read my passwords?

No. They are hashed with an algorithm designed for it and a unique salt per account; nobody — not even us — can read them. A forgotten password is reset, never recovered.

Are attachments and documents encrypted?

Yes, at rest in the file storage, and in transit every time they are opened.

Do you offer customer-managed keys?

Not as standard. If your market requires it, let's talk: we will tell you honestly what is possible and in what timeframe.

Another question? Write to us — a human will answer.

Ready to bring all your tools together?

Create your free account in two minutes: CRM, telephony, marketing, appointments and customer service — all in one place, with AI built in.

No credit card required