Defined security ownership
ImplementedTipoff assigns responsibility for access, change management, incident response, vendor risk, business continuity, and ongoing control review.
A practical overview of how Tipoff protects customer data, separates workspaces, constrains AI-assisted actions, and prepares for incidents.
Search the full public overview
We describe controls at the level customers need for vendor review. Detailed evidence and sensitive implementation information are shared through an appropriate diligence process.
Tipoff assigns responsibility for access, change management, incident response, vendor risk, business continuity, and ongoing control review.
Our control program is mapped to the AICPA Trust Services Criteria for Security. Independent examination remains future work, so we do not present internal testing as certification.
Customers may contact us for security questionnaires, data-processing terms, and available supporting material. Access to sensitive documents may require confidentiality protections.
We review material service providers and identify their role in delivering Tipoff. A provider's compliance report does not certify LinkedOtter LLC or Tipoff.
Safeguards operating today protect workspace data through layered identity, application, and database controls.
Customer records are scoped to their workspace. Authenticated requests verify workspace membership and permissions, and tenant data uses database row-level security (RLS) as an additional boundary.
Administrative and member capabilities are separated. Privileged operations are restricted to authorized personnel and scoped to the customer or operational purpose involved.
Sensitive requests revalidate the signed-in user. Enterprise customers can request SAML single sign-on with providers such as Okta, subject to configuration review and activation.
Connections use encrypted transport. Customer data and integration credentials are protected at rest, and stored secret values are not returned to the browser.
Security-relevant administrative activity is logged so access and configuration changes can be reviewed and investigated.
We limit retention according to the data and service purpose. Workspace deletion is confirmation-gated and audited, and customers can request deletion under applicable terms and law.
AI output does not grant authority. Deterministic product controls govern identity, permissions, targets, budgets, and approval.
Application changes are version controlled and pass automated quality and security checks before release. Security-sensitive changes receive additional review and validation.
Content from connected tools, files, web pages, signals, and model output is treated as untrusted input. It cannot replace system policy or create a permission.
Sensitive AI-assisted actions are checked against the authenticated user, active workspace, required capability, and action risk before execution.
External communications and other consequential operations are shown for review and require explicit user action. Approval is bound to the intended recipient and payload.
Connected services are limited to the access needed for the requested feature. Credentials stay server-side, and outbound destinations are validated before use.
Paid or autonomous operations are constrained by workspace limits and action-specific safeguards before providers are contacted.
| Data | Purpose | Service categories involved |
|---|---|---|
| Account and workspace data | Provide, secure, support, and bill for Tipoff | Hosting, database, authentication, support, and payment services |
| Customer lists and CRM records | Match, score, enrich, prioritize, and automate at the customer's direction | Configured enrichment and connected-action services |
| Public and licensed business data | Generate company intelligence and buying signals | Tipoff's processing environment and authorized data suppliers |
| AI feature inputs | Generate analysis or drafts requested by a user | The model service configured for that feature |
Hosts and serves the Tipoff application. Vercel publishes information about its own security and compliance program.
Provides managed database and authentication infrastructure. Supabase publishes information about its own security and compliance program.
Naming material infrastructure providers is a normal part of subprocessor transparency. Their certifications apply only to their defined services and audit scope.
Tipoff monitors service health, application failures, scheduled work, and security-relevant administrative activity. Alerts and evidence support investigation and control review.
Our incident process covers triage, containment, evidence preservation, recovery, customer communication, and lessons learned.
Tipoff uses managed infrastructure with backup and recovery capabilities and maintains continuity procedures appropriate to the service.
When required, affected customers are notified in accordance with applicable contracts and law, with available information about impact and response.
Customers should protect identity-provider accounts, use strong authentication, remove departed users promptly, grant only necessary roles, review staged actions before approval, keep connected-service access current, and report suspicious activity. Customers remain responsible for the lawful collection and use of data they provide to Tipoff and for actions they approve.
Machine-readable disclosure details are available at /.well-known/security.txt.