Last changed 2026-10-06
Security
How your data is held, who can reach it, and what happens when something goes wrong. Written from what the software does rather than from a template.
Who can see what
Every record belongs to one workspace, and every query is scoped to it. There is no function that loads a project from an id alone, so one studio’s records cannot be reached from another’s even by mistake.
Inside a workspace, what somebody sees depends on their role. A designer may make the work and may not decide what it sold for; a role that may set a price is not automatically one that may see what delivery costs.
Signing in
The way in is a link sent to your address. It works once, expires in twenty minutes, and is stored hashed rather than in full, so the database does not hold anything that could be used to sign in as you.
A password is optional and is yours to add or remove. It is stored with bcrypt. There is no reset flow, deliberately: the link always works, so there is no second way in to attack.
Credentials you give us
One product needs one: OB sends from your own mailbox, so it holds an application password for it. That is encrypted before it is stored, with a key held in the server environment and never in the database, so reading the database alone does not yield a usable credential.
Reading replies is optional and read-only: OB opens the mailbox without permission to change anything in it, and reads the body of a message only when it is a reply to something you sent.
Disconnecting a mailbox deletes the stored credential. Changing the password at your provider is enough on its own to stop it.
In transit and at rest
Every hostname is served over HTTPS and sends HSTS. The database is a managed MongoDB reached over TLS.
Payments are taken by Razorpay and Lemon Squeezy. Card details are entered on their systems and never reach ours, so there is no card number here to lose.
What we do not do
We do not read your records to sell to your clients. We do not pass them to anybody. Nothing in a workspace trains a model, builds a benchmark, or appears to another customer.
We do not send your data to a model at all today. Nothing in this application calls one.
If something goes wrong
Write to info@turtlelabs.co.in and say what you saw. If a breach affects your data we will tell you what happened, what was reached, and what we did, without waiting to be asked.
If you find a vulnerability, tell us before telling anybody else and we will not come after you for finding it.