Company context and lead data stay inside the workspace boundary.

Azzy does not rely on UI checks alone. Tenant isolation is enforced at the Postgres Row Level Security layer.

Workspace isolation

Every business record carries a workspace identifier. Users can only access data for workspaces where they hold a role.

Authentication

  • Supabase Auth
  • Secure sessions
  • Magic link or password
  • Team invitations
  • Role-based access

Secrets

OpenAI, Apify, Supabase secret and billing keys never ship to the browser.

Data controls

  • Export
  • Lead deletion
  • Workspace deletion
  • Suppression list
  • Audit logs
  • Retention policy

AI safety

  • Crawled pages are untrusted input
  • Prompt-injection boundaries
  • Structured Output validation
  • Unsupported-claim warnings
  • Human review for critical outputs

Outreach safety

Azzy does not automatically send email or LinkedIn messages. Every action requires human review and approval.

Certification status

SOC 2, ISO 27001, GDPR or other compliance claims will only be published after the required controls and assessments are complete.

Security contact

security@azzy.app