SECURITY

Security is a foundation, not a feature

Lettrove is built for teams that answer to auditors. Access control, an audit trail, and reviewed change management are wired in from the ground up — and our architecture is designed to make SOC 2 accreditation straightforward.

Role-based access control

Owner, admin, editor and viewer roles, enforced deny-by-default on every action. Permission checks read live membership, so revoking access takes effect immediately.

Encryption in transit & at rest

TLS everywhere. Passwords are hashed with scrypt; session, verification and invitation tokens are stored hashed, single-use and expiring.

Immutable audit trail

Every privileged action — invites, role changes, removals, sends — is recorded to an append-only log your admins can review on the Activity page.

Self-hosted identity

Your users, credentials and org membership live in our own database — not a third-party identity vendor — keeping our subprocessor list short.

Least privilege

New teammates start with only what their role needs. Admins control who can invite, change roles, and send campaigns.

Change management

Every database change ships as a reviewed, committed migration. Quality gates run on each change before it reaches production.

Working toward SOC 2

Our controls map to the Trust Services Criteria, and our change history is our evidence. Talk to us about your compliance requirements.

Create your account →