Your data. Your access rules.
Vera works with company context and connected sales tools within the access, permissions, and approval rules your organization sets.
Workspace isolation
Company context and access are scoped to your workspace.
Permissioned access
Control who can access Vera and which connected systems it can work with.
Approval controls
Decide which actions Vera can take and which require review.
Encrypted credentials
Stored connection credentials and mailbox OAuth tokens use application encryption.
Workspace isolation & access
Keep company context separated. Vera uses workspace membership and permissions to control access to company records, Company Brain, connected accounts, and actions. Company Brain records are scoped to the company, and authenticated users operate within their assigned workspace permissions. Workspace isolation is enforced at the application level and does not imply dedicated physical infrastructure.
Permissions & approvals
You decide what Vera can do. Control access to connections, campaigns, automations, sender identities, and CRM reads and writes. Require review for sensitive actions while allowing approved work to run automatically. Recurring automations can be reviewed and tested before being enabled. Campaign approval, launch permissions, sender access, and connected writes are separate controls. Available administration features depend on your plan and configured permissions.
Company Brain & continual learning
Your company context stays reviewable. Company Brain maintains shared business context with version history. Your team can review proposed changes, correct information, and restore earlier versions. Company-wide knowledge, personal preferences, and reusable working methods remain distinct forms of context. Company Brain version history describes changes to shared company knowledge, not a claim of a comprehensive audit log for every action.
Integrations & credentials
Connect only what Vera needs. Connected accounts use provider authorization together with your workspace permissions and Vera’s action rules. Stored connection secrets and mailbox OAuth tokens use application encryption. Revoke connections when access is no longer required. Revoking a connection does not automatically delete information already stored by GrowthEffect or the connected provider. Your CRM and messaging accounts remain subject to their own service terms. Transport, storage, backups, and key-management requirements can be reviewed for your deployment; credential encryption is not a blanket guarantee for every data store.
AI & data processing
Company context supports the work you give Vera. Tasks may provide relevant instructions, company context, and permitted tool results to AI and service providers required to complete the work. What is processed depends on the task, integrations, and tools involved. Discuss provider processing terms, sensitive-data requirements, and any model-training restrictions before rollout. This page does not make a blanket model-training commitment across all providers.
Retention, privacy & infrastructure
Know how your data is handled. Company context, task records, connection data, and other stored information serve different purposes and may have different retention periods. GrowthEffect uses hosted infrastructure, AI processing, connection services, and other providers to deliver Vera. Contact us for retention requirements, deletion requests, provider information, processing locations, or contractual documentation. Removing a connection, archiving a task, and deleting stored data are different operations. Account-specific retention, contractual requirements, and backup handling should be agreed with GrowthEffect.
Privacy & compliance
Talk to GrowthEffect about processing roles, contractual documentation and relevant providers. Compliance depends on your organization’s use, configuration, and legal requirements. GrowthEffect product controls alone do not establish compliance.
- GDPR & KVKK: Processing roles and contractual requirements.
- Cross-border processing: Relevant providers and processing locations.
- Data retention: Account-specific retention and deletion requirements.
- Subprocessors: Providers relevant to your GrowthEffect deployment.
Found a security issue?
Contact hello@growtheffect.co with the affected product, approximate time and a concise description. Do not send passwords, access tokens or unrelated customer data. Privacy and deletion requests: info@growtheffect.co.
Security review for your organization
Discuss your questionnaire, procurement requirements, and the documentation or contractual assurances currently available for your deployment.