Skip to contentSkip to main content

Security and data responsibility

Protect customer and quote data with clear account boundaries

OfferAgent protects customer and quote workflows through authenticated access, tenant-scoped backend authorization, database policies where applicable, immutable sent revisions, append-only event history and restricted public tokens. Security remains a shared responsibility: each customer controls users, lawful data collection, configured integrations, retention choices and who may act on customer information.

Trust depends on boundaries that also work at runtime

A security page should not be a list of unsupported certifications. Buyers need to understand identity, tenant isolation, public-link boundaries, auditability, provider responsibilities and the controls they must configure themselves.

How is access separated?

  1. 01

    Authenticate the user

    Private workspaces require a valid session before account capabilities are loaded.

  2. 02

    Resolve the tenant

    Backend services derive the account context and scope reads and writes to that account.

  3. 03

    Check role and entitlement

    Administrative actions and package capabilities are evaluated separately from navigation visibility.

  4. 04

    Record consequential events

    Revision, send, view, contact, automation and acceptance events remain attributable.

Product evidence: controls at each boundary

The platform separates private account access, public token access, immutable quote artifacts and outbound provider delivery instead of treating security as one login screen.

  • Private and transactional routes are noindex
  • Account authorization is enforced by backend contracts
  • Accepted revisions cannot be silently rewritten
Verified control boundaries
Private account access
Account authorization is enforced by backend contracts
Shared responsibility: OfferAgent verifies session, tenant and authorization. The customer manages users and offboarding.
Sent and accepted quotes
Accepted revisions cannot be silently rewritten
Shared responsibility: OfferAgent preserves revision linkage. The customer is responsible for content and recipients.
Public and transactional surfaces
Private and transactional routes are noindex
Shared responsibility: OfferAgent restricts the resource and search indexing. The customer shares links with intended recipients.

Core safeguards in the platform

Tenant isolation

Service-layer account checks and database policies protect account-scoped records.

Revision integrity

Sent quote content, calculated totals, PDF snapshot and acceptance stay tied to the saved revision.

Restricted public surfaces

Public quote and form URLs expose only the intended resource and are excluded from search indexing.

Audit history

Canonical events preserve actor, account, object and time for consequential workflow changes.

Transport and providers

Production uses HTTPS. Hosting, database, payment, email and optional AI providers have separate responsibilities and terms.

Privacy-minimized measurement

Website measurement starts only after an explicit choice. OfferAgent's own conversion events use a random identifier limited to the browser tab. Google Analytics may set pseudonymous measurement cookies after consent. Analytics events exclude names, email addresses, form content and quote identifiers, while Google signals and advertising personalization remain disabled. Global Privacy Control and Do Not Track disable measurement.

Shared responsibility and current boundaries

OfferAgent does not claim certifications or contractual guarantees that are not published and verified. A production agreement must identify the legal operator, subprocessors, retention, support channel and applicable data-processing terms.

  • Customers manage users, roles and offboarding
  • Customers define lawful purpose, consent and retention
  • Integration credentials and destination systems require separate review

Questions about security and privacy

Can users see another customer's data?

Account-scoped backend checks and applicable database policies are designed to prevent cross-tenant access. Security tests must continue to verify this boundary.

Are public quotes indexed by search engines?

No. Public quote routes send noindex headers and use restricted identifiers rather than appearing in the marketing sitemap.

Where is data processed?

Processing location depends on the configured hosting, database, communication, payment and optional AI providers. Contractual provider details must be confirmed before production use.

Does OfferAgent have a security certification?

No certification is claimed on this page. Any future certification will be published only with verifiable scope and dates.

Does marketing measurement identify visitors?

OfferAgent does not send names, email addresses, form content or quote identifiers to analytics. Its own funnel identifier exists only in the current browser tab. After consent, Google Analytics may assign a pseudonymous browser identifier through measurement cookies. Google signals and advertising personalization are disabled. Payment completion is recorded by the server from the checkout lifecycle.