Tenant isolation
Service-layer account checks and database policies protect account-scoped records.
Security and data responsibility
OfferAgent protects customer and quote workflows through authenticated access, tenant-scoped backend authorization, database policies where applicable, immutable sent revisions, append-only event history and restricted public tokens. Security remains a shared responsibility: each customer controls users, lawful data collection, configured integrations, retention choices and who may act on customer information.
A security page should not be a list of unsupported certifications. Buyers need to understand identity, tenant isolation, public-link boundaries, auditability, provider responsibilities and the controls they must configure themselves.
Private workspaces require a valid session before account capabilities are loaded.
Backend services derive the account context and scope reads and writes to that account.
Administrative actions and package capabilities are evaluated separately from navigation visibility.
Revision, send, view, contact, automation and acceptance events remain attributable.
The platform separates private account access, public token access, immutable quote artifacts and outbound provider delivery instead of treating security as one login screen.
Service-layer account checks and database policies protect account-scoped records.
Sent quote content, calculated totals, PDF snapshot and acceptance stay tied to the saved revision.
Public quote and form URLs expose only the intended resource and are excluded from search indexing.
Canonical events preserve actor, account, object and time for consequential workflow changes.
Production uses HTTPS. Hosting, database, payment, email and optional AI providers have separate responsibilities and terms.
Website measurement starts only after an explicit choice. OfferAgent's own conversion events use a random identifier limited to the browser tab. Google Analytics may set pseudonymous measurement cookies after consent. Analytics events exclude names, email addresses, form content and quote identifiers, while Google signals and advertising personalization remain disabled. Global Privacy Control and Do Not Track disable measurement.
OfferAgent does not claim certifications or contractual guarantees that are not published and verified. A production agreement must identify the legal operator, subprocessors, retention, support channel and applicable data-processing terms.
Account-scoped backend checks and applicable database policies are designed to prevent cross-tenant access. Security tests must continue to verify this boundary.
No. Public quote routes send noindex headers and use restricted identifiers rather than appearing in the marketing sitemap.
Processing location depends on the configured hosting, database, communication, payment and optional AI providers. Contractual provider details must be confirmed before production use.
No certification is claimed on this page. Any future certification will be published only with verifiable scope and dates.
OfferAgent does not send names, email addresses, form content or quote identifiers to analytics. Its own funnel identifier exists only in the current browser tab. After consent, Google Analytics may assign a pseudonymous browser identifier through measurement cookies. Google signals and advertising personalization are disabled. Payment completion is recorded by the server from the checkout lifecycle.