← Learn
Security · beginner

Security and privacy at Tipoff

A ~380-word help-center article explaining Tipoff's security and privacy posture: tenant isolation, encryption in transit/at rest, encrypted BYO keys, public-only signal pooling, and company-level reveal.

Tipoff handles your account lists, enrichment data, and site-visitor signals, so you should know exactly how that data is protected and where the boundaries are. This article explains how we isolate your workspace, encrypt your data, and keep our reveal features privacy-first.

Your data stays in your workspace

Every account, contact, list, and signal you create lives in your own tenant. We enforce strict tenant isolation at the data layer: one customer's data is never readable by another, and it is never used to enrich, score, or train against another customer's accounts. When you enrich a contact or tier an account against your ICP corpus, that work runs against your data only.

Encryption in transit and at rest

All traffic between your browser, our API, and connected tools is encrypted in transit using TLS. Data stored on our side, including your accounts, enrichment results, and signal history, is encrypted at rest. This applies to every capability metered in Tipoff credits, from signal collection to reveal.

Your connected keys are encrypted

When you bring your own provider keys or connect HubSpot, Pipedrive, Prosp, Instantly, Slack, or Zapier, those credentials are encrypted before storage and used only to run the integrations you turned on. We never expose your keys back to you in plaintext or share them across workspaces.

Only public business signals are pooled

Tipoff builds signal coverage from public business sources: job posts, regulatory filings, news, and community activity. Only this public, company-level signal layer is shared across the platform to improve detection for everyone. Your private inputs, such as your account lists, notes, ICP definition, CRM data, and enrichment outputs, are never pooled.

Company-level reveal, not individuals

Our site-reveal feature identifies which companies visit your site, not which people. It is company-level by design and honors visitor privacy signals such as Global Privacy Control and Do Not Track. We do not build individual visitor profiles or fingerprint people. You can also run audit and deletion requests from the integrations settings if you need to remove data.

Related

See "Bring your own keys," "Set up site reveal," and "Manage integrations and data deletion" for step-by-step configuration.

Maintained by Tipoff Team · reflects 2026.07Last updated 2026-07-16
Was this helpful?