Data in transit
Encrypted HTTPS/TLS connections for all communication between browser and ReachFalcon services.
Authentication
Secure account access systems. Passwords are not intentionally stored in readable plain text.
Mailbox connections
Scoped token and authorization methods. Saved mailbox credentials are not exposed through the UI.
Access control
Internal production access is restricted based on operational need, role boundaries, and security.
Infrastructure
Multi-layered network safeguards, dependency maintenance, abuse prevention, and logging.
Responsible disclosure
Private vulnerability intake and fast containment for reports submitted in good faith.
Protecting customer data, prospect information, connected mailboxes, and campaign infrastructure is an important part of how ReachFalcon is designed and operated.
No online service can promise perfect security, but we use technical and operational safeguards intended to reduce security risks.
Data in Transit
ReachFalcon uses HTTPS/TLS for supported communication between your browser and our application.
This helps protect information while it travels across the internet.
Authentication
Account authentication is handled through secure authentication systems.
We do not intentionally store user passwords in readable plain text.
Users are responsible for:
- Protecting their login credentials
- Keeping access to their email account secure
- Using strong passwords
- Preventing unauthorized access to their devices
- Removing team members who no longer require access
Mailbox Connections
ReachFalcon may connect to email accounts through supported authorization or mailbox connection methods.
Access credentials, tokens, or mailbox configuration are used only as needed to provide requested functionality.
We do not intentionally expose complete saved mailbox credentials through the normal user interface after they have been securely stored.
Access Control
Access to production systems and customer information is limited to people and systems that require access to operate, secure, maintain, or support ReachFalcon.
Internal access should be based on legitimate operational need.
Customer Data
ReachFalcon processes only the information needed to provide requested features.
This can include:
- Account data
- Prospect lists
- Campaign content
- Personalized assets
- URLs
- Mailbox information
- Delivery information
- Replies
- Product usage data
Customers remain responsible for deciding which prospect information they upload.
Payment Security
Payment information is handled through supported payment providers.
ReachFalcon does not need to store full payment card information when a payment provider handles the transaction.
Infrastructure Protection
We use security controls intended to protect ReachFalcon's infrastructure, including measures related to:
- Authentication
- Access restrictions
- Network security
- Application security
- Logging
- Abuse prevention
- Service monitoring
- Dependency maintenance
Security controls may evolve as the platform grows.
Abuse Protection
ReachFalcon may automatically or manually restrict activity that appears to involve:
- Fraud
- Phishing
- Malware
- Account compromise
- Excessive automated abuse
- Illegal spam
- Attempts to attack ReachFalcon infrastructure
Accounts creating a serious security risk may be suspended immediately.
Third-Party Providers
Like most SaaS products, ReachFalcon relies on specialist infrastructure providers.
We evaluate service providers based on factors such as functionality, reliability, security, and data handling appropriate to the service they perform.
Data Backups and Recovery
We use infrastructure and operational processes designed to reduce the risk of permanent data loss.
However, users should not treat ReachFalcon as the sole permanent backup location for business-critical information.
Security Incidents
If we identify a security incident involving customer information, we will investigate it and take appropriate containment and remediation measures.
Where applicable law requires notification, affected customers or authorities will be notified as required.
Your Security Responsibilities
Security is shared between ReachFalcon and its users.
You should:
- Protect your account credentials
- Protect connected mailbox credentials
- Restrict workspace access
- Review team members periodically
- Use secure domains and mailboxes
- Avoid uploading unnecessary sensitive information
- Report suspicious activity promptly
Sensitive Information
ReachFalcon is not designed as a system for storing highly sensitive categories of information such as:
- Medical records
- Financial account passwords
- Government identification documents
- Payment card databases
- Authentication secrets unrelated to supported integrations
Do not upload sensitive information unless necessary for an expressly supported feature.
Responsible Disclosure
If you believe you have discovered a security vulnerability in ReachFalcon, please report it privately.
Email: support@reachfalcon.com
Subject: Security Report
Please include:
- Description of the issue
- Affected page or feature
- Steps to reproduce it
- Potential impact
- Screenshots or technical details where useful
Please do not:
- Access information belonging to another customer
- Destroy data
- Perform denial-of-service attacks
- Use social engineering
- Publicly disclose an unresolved vulnerability before giving us reasonable time to investigate it
Good-faith security reports are appreciated.
Security Questions
For security-related questions: