Security & Privacy
Managed storage supports features such as Unibox and campaigns. Export and deletion options follow the lifecycle and exceptions described in our Privacy Policy.
Your data, your rules
Managed storage powers features such as Unibox. Export and deletion options follow the lifecycle, limitations, and exceptions described in the Privacy Policy.
Controlled credential handling
Crispy supports hosted connection and direct credential or session-cookie methods. Connection material is sent to the connection provider and may be stored where technically needed to operate and secure the session.
API keys hashed at rest
API keys are stored as SHA-256 hashes. The plaintext key is shown once at creation and cannot be retrieved. Revoke any key instantly from the dashboard.
Permission scoping
Each connected profile has granular permission scopes. Restrict tools to read-only, outbound-only, or full access. Employees control their own scope.
Infrastructure
Hosted on Railway with Supabase database controls, including row-level security represented in repository migrations. Production regions and transport configuration still require verification.
Privacy controls
A DPA is available upon request for eligible customer agreements. Data-rights information is public; final execution terms, vendor contracts, regions, and transfer mechanisms require verification and approval.
What data touches our servers?
The service stores and processes the categories described below.
| Data type | Stored? | Details |
|---|---|---|
| Contacts & activities | Managed (default) | Stored for Unibox & campaigns. Export and deletion options follow the Privacy Policy lifecycle |
| LinkedIn credentials | Provider-managed | Credentials or session material can be received and transmitted to the connection provider and stored where technically necessary |
| API keys | SHA-256 hash only | Plaintext shown once, then discarded |
| Usage logs (tool name, timestamp) | 90 days | Rate limiting & analytics only |
| Email & billing | While active | Local account teardown applies, while exact billing, vendor, audit, and legal retention schedules remain under review |
Security FAQ
Do you need a DPA (Data Processing Agreement)?
Managed storage can process contact and activity data on your behalf. A DPA is available upon request for eligible customer agreements and becomes effective only through valid execution or incorporation.
What happens if Crispy gets breached?
Managed storage can contain contacts, messages, activity, and LinkedIn session material. API keys are SHA-256 hashed in the documented generation path. See the Privacy Policy and draft security annex for current limitations and pending verification.
Can my employer see my LinkedIn messages?
Only if you grant them access. Each team member controls their own permission scope. An admin can see usage logs (which tools were called) but message content is only accessible through the Unibox if the account is in their workspace.
How do daily safety limits work?
Crispy enforces per-profile daily action caps (connection requests, messages, posts) that stay within LinkedIn's acceptable usage patterns. These limits cannot be overridden, even by API.
Is Crispy SOC 2 certified?
Crispy itself is not SOC 2 certified. The repository uses Railway hosting and Supabase database controls, including row-level security migrations. Production transport, regions, and control effectiveness still require verification.
Can I run a pentest against Crispy?
Yes. Contact us at [email protected] to coordinate. We welcome responsible disclosure.
The complete LinkedIn API. Ready when you are.
Connect your first LinkedIn profile in under 5 minutes. Every tool, every seat, no feature gates. Safe limits, warm-up, and full permission control built in.