Security and access control
CloudSun enforces permission checks at the data layer, not just by hiding buttons in the browser.
Verified identities
Google identity sign-in with optional email/password fallback. Mobile number verification via OTP.
Role-based access
Nine default roles with explicit permissions enforced at the data-access layer, not just in the browser.
Organisation isolation
Strict tenant isolation with organisationId scoping on every query.
Audit history
Fourteen sensitive action types audit-logged with user, timestamp, and context.
Revocable sessions
Database-backed sessions with per-device revocation and sign-out-everywhere support.
Permission-based records
Contacts, conversations, and campaigns are scoped by team and role permissions.
Honest integration states
All integrations are truthfully labelled: connected, demonstration, or planned.
Honest about certifications: CloudSun has not obtained SOC 2, ISO 27001, HIPAA, or other formal certifications. We do not claim certifications we have not earned. Security practices are implemented following industry best practices, and formal certification is a planned future initiative.