> Lettrove docs 1.x · https://docs.lettrove.com/docs/app/security

# Security

Lettrove is built for teams that answer to auditors. Access control, an audit trail and reviewed
change management are wired in from the ground up, and the architecture is designed to make SOC 2
accreditation straightforward: the controls map to the Trust Services Criteria, and the change
history is the evidence.

## Access

- **Four roles** (owner, admin, editor, viewer), enforced deny-by-default on every action, in the
  API and the app from one catalogue so the two cannot disagree. Checks read live membership, so
  revoking access takes effect immediately. New teammates start with only what their role needs.
  [Roles](/docs/app/team#roles).
- **Workspaces are isolated.** Every record belongs to one workspace, and every read and write is
  scoped to it.
- **Two-factor authentication** is available to every account under Settings → Security.

## Credentials and tokens

- TLS everywhere.
- Passwords are hashed with scrypt. Session, verification and invitation tokens are stored hashed,
  single-use and expiring.
- Your users, credentials and workspace membership live in Lettrove's own database, not a third-party
  identity vendor, which keeps the subprocessor list short.
- Integration tokens (HubSpot's OAuth tokens) are encrypted at rest with AES-256-GCM, never shown
  and never logged. Secret keys for the embedded editor are kept only as a keyed fingerprint.
- Apps you connect through the MCP server get short-lived OAuth 2.1 tokens bound to the server's
  address, and can be disconnected in one click.

## The activity log

Every privileged action (invites, role changes, removals, sends, integrations, keys) is recorded to
an append-only log that admins review on the Activity page. [The activity log](/docs/app/team#the-activity-log).

## Change management

Every database change ships as a reviewed, committed migration. Each change to the product passes
quality gates (typecheck, tests, lint, build, end-to-end tests) before it can reach production, and
production is deployed from the main branch only.

## Email you send

Unsubscribe links and tracking links are signed per recipient and carry nothing personal in the
address, so a link cannot be edited to act for someone else. [Sending](/docs/app/sending).

## Questions

Security reports and questions about your compliance requirements: support@lettrove.com.

If you embed the editor in your own product, [Security for the embed](/docs/going-live/security) and
[What Lettrove stores](/docs/data/what-we-store) cover that side.
