Security

HypeSync sits between your reps' LinkedIn inboxes and your CRM. Here is exactly how that boundary is protected.

We never see your CRM password

Salesforce and HubSpot connect through OAuth: you sign in on their domain, and they hand HypeSync a scoped token. We can log activities and manage the records the integration needs — nothing more — and you can revoke access from your CRM at any time.

Tokens are encrypted at rest

CRM access and refresh tokens are encrypted with AES-256-GCM before they touch the database. In production the app refuses to start without a proper encryption key — there is no insecure fallback.

Personal conversations never reach your CRM

AI triage classifies every conversation, and anything personal — friends, recruiters approaching you, vendors pitching you — stays out of the CRM. You can add keyword guardrails that force specific conversations to always stay private, overriding the AI.

No automation on your LinkedIn account

HypeSync never sends messages, never auto-connects, never views profiles, and never runs sequences. It reads the conversations already in your own inbox as you browse. This is a design constraint, not a setting — it is what keeps reps' accounts safe.

We store previews, not archives

Capture is limited to your own inbox, and what we keep server-side is minimised: message previews for triage and logging, not a full archive of your LinkedIn history. The complete activity record lives where it belongs — in your CRM.

The boring parts, done properly

Payments run through Stripe (we never touch card numbers). Authentication runs through Clerk, with SSO on the Team plan. Inbound webhooks are signature-verified, public endpoints are rate-limited, and every workspace's data is isolated. A DPA is available for customers who need one.

Questions about a security review or the DPA? Get in touch — we answer these directly.