Skip to main content
Ridhzo — Leads Move Faster

Security & Data Isolation

Sales leads represent your company's most sensitive revenue pipeline. We build security into every layer of Ridhzo — from workspace-scoped queries to signed webhook validation.

Last updated: September 30, 2026
Effective: September 30, 2026
v2.1

1. Security Design Principles

Ridhzo is designed on the principle of least privilege and strict separation between workspaces. Because the platform handles inbound enquiries and deal pipelines, every layer is built to prevent unauthorized access and data leakage:

Tenant Partitioning

Every query is scoped to your workspace, so one business can never see another's leads.

Encrypted Secrets

Email passwords, integration tokens and webhook secrets are encrypted with AES-256-GCM before they are stored. All traffic uses HTTPS.

Auditability

An audit log records who changed settings, roles and users, who deleted or merged leads, and who created API keys.

2. Workspace Isolation

Ridhzo runs on PostgreSQL, with workspace boundaries enforced in the application on every request:

  • Workspace scoping: Every lead, note, custom field, pipeline stage and sequence belongs to exactly one workspace, and every query is limited to the signed-in person's workspace.
  • Parameterized queries: Database queries use typed, parameterized statements. Raw user strings are never concatenated into SQL, which removes the SQL-injection attack surface.
  • Permissions checked on the server: What a person can see or do is enforced by the server on every request — not just hidden in the interface. Sales reps can open only the leads assigned to them.

3. Encryption

Sensitive secrets: AES-256-GCM

Credentials such as email (SMTP) passwords and integration access tokens are encrypted at the application level with AES-256-GCM before they are saved, using a fresh random value for every encryption. A tampered value fails to decrypt. API keys are stored hashed, so they can't be read back.

In transit: HTTPS

Traffic between your browser or phone and Ridhzo is encrypted with HTTPS (TLS). Account passwords are stored as hashes, never in plain text.

4. Webhook Integrity & HMAC Verification

Because leads stream in from external advertising networks, we verify the authenticity of incoming requests before parsing them:

  • Meta Facebook Lead Ads: We inspect the X-Hub-Signature-256 header on every inbound webhook, verifying the SHA-256 HMAC payload against your App Secret. Payloads with invalid or missing signatures are rejected before anything is saved.
  • Google Lead Form and website webhooks: Inbound requests are matched against the secret key configured for that source. Optional HMAC signatures are supported for custom webhooks.
  • Outbound webhooks are signed (HMAC-SHA256), so your systems can verify a delivery came from Ridhzo. Public forms and webhooks are rate-limited against spam.
  • Duplicate protection: Retried deliveries don't create duplicate leads.

5. Mobile Apps & Offline Data

Ridhzo lets reps in the field add new leads even without a network connection. How that data is handled depends on how the app is installed:

  • Web app (PWA): Offline mode holds only leads a rep has just added. Existing leads are not downloaded for offline use. Pending leads are kept in the browser's storage for the Ridhzo app, separated per workspace and not readable by other websites.
  • Android app: To work offline and to identify callers, the app keeps a copy of the leads that person is allowed to open on the phone. We recommend a screen lock on work phones, and a lost phone's access can be cut off by deactivating the user.
  • Call logging stays private: The Android app matches its call log against your leads' numbers and sends only those calls. Personal calls never leave the phone, and nothing is read until the rep grants the call-log permission.
  • Normal checks on sync: When the connection returns, each offline lead goes through the same signed-in, permission-checked path as any other new lead — including duplicate detection.

6. Role-Based Access Control (RBAC)

Every person has a role. Ridhzo ships an Admin and a Member role, and you can create custom roles from 14 separate permissions:

RoleScope of AccessBilling & Settings
AdminEverything: all leads, team members, roles, integrations, webhooks, API keys, audit logFull (billing, settings, permanent lead deletion)
Member (sales rep)Their own assigned leads only: create, edit, call, message, change statusNone by default (cannot delete or purge leads, or change settings)
Custom rolesAny combination of the 14 permissions — for example a read-only Viewer for a partnerOnly what the role is explicitly granted

Someone who can invite people but cannot manage roles is not able to hand out a role with more access than they hold themselves.

7. Deletion, Retention & Recovery

You stay in control of your data, including when it leaves Ridhzo:

  • 30-day recycle bin: Deleted leads can be restored for 30 days, guarding against accidental deletion.
  • Permanent deletion: People with the purge permission can erase leads for good, and a lead's data can be exported or erased on request.
  • Export: Leads can be exported to CSV by people with permission.
  • Audit trail: Deletions, merges and permission changes are recorded with who did them and when.

8. Responsible Vulnerability Disclosure

We welcome collaboration with independent security researchers to uncover potential flaws. If you discover a security vulnerability in Ridhzo:

Vulnerability Disclosure Protocol

Please report all potential security issues directly to [email protected] with reproduction steps and proof-of-concept logs.

  • We acknowledge verified reports within 24 hours.
  • We commit to not pursuing legal action against researchers acting in good faith.
  • Please allow reasonable time for remediation before public disclosure.
Questions or Inquiries?

Our compliance and data protection team responds to all inquiries within 24 hours.