Security
Security & Data Isolation
Every organisation on GlobifyAI operates in its own fully isolated space. Here's exactly how that's built and enforced — not just claimed.
Your business data — leads, conversations, campaigns, call recordings, knowledge base, everything — is only ever visible to your own organisation. This page explains how that separation is built, so you can evaluate it rather than just take our word for it.
1. Data Isolation
GlobifyAI is a multi-tenant platform: every customer's business runs in the same application, on separate, walled-off data. Your CRM leads, inbox conversations, WhatsApp and Telegram messages, email campaigns, ad campaigns, AI phone calls and transcripts, calendar, knowledge base, notifications, and billing history belong exclusively to your organisation.
No other customer — regardless of plan, account age, or how their request is formed — can read, modify, delete, or receive your data through the product, its API, or its background processes.
2. How Isolation Is Enforced
Isolation is not a frontend convenience — it's enforced independently at two layers, so a mistake in one doesn't expose the other:
2.1 Server-side authorisation
Every request to our API is authenticated against a server-validated session. Your organisation is resolved from that verified session — never from anything a request could claim about itself (a URL, a form field, a hidden parameter). Changing an ID in a request doesn't change whose data you're allowed to touch.
2.2 Database-level policies
Beneath the API, our database enforces Row Level Security — rules living in the database itself that restrict which rows a query can ever return, independent of the application code that wrote the query. This is a second, independent backstop under the server-side checks, not a replacement for them.
3. Encryption
- All data in transit is encrypted via HTTPS/TLS
- Sensitive credentials — API tokens, OAuth access tokens, phone provider credentials — are encrypted at rest using AES-256-GCM before storage
- Passwords are never stored in plain text or reversibly encrypted
4. AI Data Isolation
Every AI request — content generation, chat replies, call handling, lead scoring — is scoped to your organisation for that request only:
- Your Knowledge Base is retrieved only for your own AI requests, never surfaced to another customer
- AI conversation history and memory are stored per-organisation and never merged across accounts
- Business context used to ground AI output (your business info, tone, past performance) is fetched fresh per request from your own records
- GlobifyAI does not train shared models on your private business data
5. Independent Testing
We run our own adversarial testing against isolation controls on a recurring basis: two separate test accounts, one seeded with marked data, actively attempting to reach the other's data through the UI, the API, direct record IDs, storage, search, notifications, AI requests, and scheduled background jobs. We treat any finding as a P0 issue — fixed and re-verified with a live cross-account test before being considered resolved, not just documented.
6. Infrastructure
- Hosted on established cloud infrastructure (Vercel, Supabase) with their own SOC 2-aligned operational controls
- Database backups are isolated per environment and access-restricted to authorised infrastructure only
- Production access is restricted to the engineering team and logged
7. Your Responsibilities
Isolation protects you from other customers — you're still the first line of defence for your own account:
- Use a strong, unique password and enable any available account protections
- Only grant team members the access level they actually need
- Revoke integrations (social accounts, CRM connections, phone numbers) you're no longer using
8. Reporting a Vulnerability
If you believe you've found a way to access another organisation's data, or any other security issue, please tell us before disclosing it publicly. We take every report seriously and will investigate promptly.
Email: support@globifyai.com
Please include enough detail to reproduce the issue. Do not access, modify, or exfiltrate another customer's data while testing — report what you found instead.
See also our Privacy Policy for how we collect and use data, and our GDPR page for your data rights.