Data Security Policy
Last updated: October 2026
Agencies keep their leads, their clients' details and their invoices in Vridesk. This page explains, in plain words, how that data and the accounts that reach it are protected.
1. Scope
This policy covers the Vridesk web application: the agency workspace, the client portal and the accounts used to sign in to them. It describes the measures built into the product. It is not a certification, and Vridesk does not currently hold any third-party security certification.
How we collect and use personal information is covered separately in our Privacy Policy.
2. Workspace Isolation
Every agency that registers on Vridesk gets its own workspace. Leads, contacts, deals, clients, projects, tasks, invoices, campaigns, inbox messages, automations and settings all belong to exactly one workspace.
- Every request for CRM data is checked against the workspace of the signed-in user, so one agency cannot open, change or delete another agency's records - even with a direct link to them.
- Client email addresses and invoice numbers are unique within a workspace, not across Vridesk, so one agency's records never collide with another's.
- When a workspace's trial or plan ends, the workspace is locked and its data is not loaded until a plan is active again.
3. Account Security
3.1 Passwords
- Passwords are stored only as argon2id hashes. Nobody at Vridesk can read your password.
- Changing your password requires your current password, and signs out every other device.
- Password reset links are single-purpose, expire, and are sent only to the email address on the account.
3.2 Signing In
- A new account is confirmed with a one-time code sent to its email address.
- Signing in from a device we have not seen recently asks for a one-time code sent to your email.
- You receive an email alert when your account is signed in to from a device we have not seen recently.
- Sign-in, sign-up, one-time code and password reset requests are rate-limited to slow down guessing.
3.3 Sessions and Devices
- Each device you sign in on has its own session, kept in a cookie that scripts on the page cannot read.
- Sessions expire after 7 days. Settings shows every device that is signed in, and you can sign out of all of them at once.
- App Lock lets you protect an open workspace with a 4 to 6 digit PIN that is asked for again after a period of inactivity or when the browser is reopened.
4. Roles Inside a Workspace
- The workspace owner adds team members, can suspend or remove them, and is the only person who can change the connected mailbox and invoice details.
- Team members can use the CRM of their own workspace, but cannot manage the team or its settings. The owner can give a member a role that limits which areas they can open or change; without a role a member can use the whole CRM.
- What the team adds, changes, sends and deletes in the CRM is recorded in the workspace's activity log, with the member's name and the time.
- Each user can see their own account activity (sign-ins, password changes, App Lock changes) with the date, time and network (IP) address, from the notification bell.
- A suspended member, or a member of a suspended workspace, cannot sign in.
5. Your Connected Mailbox
To send campaigns and read replies, an agency connects its own email account to Vridesk.
- The mailbox password is encrypted with AES-256-GCM before it is saved, and it is never sent back to the browser - not even to the owner who entered it.
- Vridesk connects only to public mail servers on the standard secure mail ports.
- Your mailbox is used only for your own workspace: to send your campaigns and automation emails, and to bring replies from your leads into your Inbox.
- The owner can disconnect the mailbox at any time, which removes the saved password.
6. Client Portal
- A client signs in to the portal with the email address and the portal password set by the agency. Portal sign-ins are kept completely separate from staff accounts.
- A client sees only their own onboarding checklist, projects, tasks, proposals, contracts and invoices. Drafts are never shown in the portal.
- When a client signs a contract in the portal, the name they typed, the date and time, and their network (IP) address are stored with the contract. A signed contract's text can no longer be changed.
- Portal passwords are stored as argon2id hashes, the same as staff passwords.
7. Application Safeguards
- Pages are served with a strict content security policy, and browsers are told not to load Vridesk inside a frame on another site.
- Browsers are instructed to connect to Vridesk over HTTPS only.
- Passwords, one-time codes, reset links and mailbox credentials are not written to our application logs.
- Plan changes made on a workspace are recorded in an audit log.
8. Deleting Your Data
The workspace owner can delete the account from Settings after typing the account email address to confirm. This permanently removes the workspace together with its team members and all of its CRM data, and it cannot be undone.
Team members are removed by the workspace owner. Removing a member does not delete the leads or clients they worked on.
9. Your Responsibilities
Security also depends on how a workspace is used. We ask every agency to:
- Use a strong password that is not used anywhere else, and never share an account between people.
- Give each client their own portal password, and share it with them privately.
- Remove or suspend team members as soon as they leave.
- Keep the devices and the email accounts used with Vridesk secure, because one-time codes and reset links are sent by email.
10. Reporting a Security Concern
If you believe you have found a security problem in Vridesk, or you think your account has been used by someone else, write to us at vridesk@vriyox.com with as much detail as you can. Please do not share the details publicly until we have had a chance to look into it.
Messages that claim to be from Vridesk but do not come from an official Vriyox address should be treated as unauthorised - see Contact for our official details.
11. Changes to This Policy
We update this policy when the product's security measures change. The date at the top of the page shows when it was last revised.