Security

Built for the most sensitive conversations in your agency.

Rapport Studio reads client calls and emails. That access is scoped, verified, and logged, the same way you'd expect from anything given a key to your inbox.

Google OAuth verified ADA-CASA AL1 passed

rapportstudio · security

Google OAuth verificationPassed
ADA-CASA AL1 assessmentPassed
Gmail permission requestedgmail.readonly

Read-only. Matched. Nothing else.

Gmail uses a read-only permission. It does not grant permission to send, edit or delete messages.

  • gmail.readonly, not gmail.modify or gmail.send
    The permission to send, delete, or edit email was never requested, and the product has no code path that could use it.
  • Matched to known client domains only
    Messages are matched to known client domains or saved contact addresses before they are stored and analysed as client conversations.
  • Disconnect in one click
    Revoking access is immediate and available from your own settings at any time, no support ticket required.

Gmail permission requested

scope: https://www.googleapis.com/auth/gmail.readonly

✕ Cannot send email

✕ Cannot delete email

✕ Cannot modify labels or folders

✓ Can read messages matched to a client domain

Independently verified, not self-declared.

Two separate outside reviews, not a claim on a website.

Google OAuth app verification

Required by Google for any app requesting a restricted Gmail scope. Google reviews what the app actually does with the data before granting access, not just what it says it does.

ADA-CASA AL1 assessment

The independent security assessment Google requires at this access level before a restricted scope is approved for production use. Rapport Studio has passed it.

How access is protected.

Controls used across the application and API.

Encrypted in transit

Every connection to Rapport Studio runs over HTTPS. Nothing is sent in the clear.

Passwords, never stored

Passwords are hashed before they ever touch the database. Nobody at Rapport Studio can read yours.

Rate limited

API and authentication routes apply request limits to reduce repeated login attempts and abuse.

Validated inputs

Input checks and access controls protect application routes. Checks depend on the operation being performed.

Security headers enforced

Standard protections against clickjacking, sniffing and injection are on by default, not opt-in.

Workspace activity logged

Actions inside your workspace are recorded to an audit trail your team can review.

Access matches the role, nothing more.

Account managers see their own clients. Managers see the whole agency. Rapport Studio's own team never touches your data through your account.

  • Role-based access
    What a teammate can see is scoped to their role, not an all-or-nothing switch.
  • Internal tooling, fully separated
    Staff who support your account use a different login system entirely, with its own access controls.
  • SSO for Enterprise
    Single sign-on and additional compliance controls are available on the Enterprise plan.

Account separation

Your workspace

Account managers, leads, owners

Rapport Studio staff

Separate login system, separate database table

There is no shared account table between the product and internal tooling. Customer and staff access use separate authentication and role checks. Staff tools still require controlled access to shared service data.

Questions your security team would ask, answered.

Happy to walk your IT or security lead through this directly before you connect anything.