🔒 Security

Built secure.
Kept secure.

SideBlend is designed with enterprise-grade security practices from the ground up. We follow SOC 2 standards to protect your data, your credentials, and your customers’ information — every step of the way.

🏅
SOC 2 Aligned
Security, Availability & Confidentiality controls
🔐
Encrypted in Transit
TLS 1.2+ for all data in motion
🟢
Zero Data Retention
Your CRM data is never stored on our servers

Aligned with the Trust Services Criteria

SOC 2 (Service Organization Control 2) is the leading security and compliance framework for SaaS companies. It defines controls across five Trust Services Criteria. SideBlend is built in alignment with these principles to give your team and your customers confidence.

Security
Systems are protected against unauthorized access, both physical and logical.
Availability
The system is available for operation and use as committed or agreed.
Confidentiality
Information designated as confidential is protected as committed or agreed.
Processing Integrity
System processing is complete, valid, accurate, timely, and authorized.
Privacy
Personal information is collected, used, retained, and disclosed in conformity with privacy commitments.
🏅
SOC 2 Aligned
Trust Services Criteria
SecurityAvailabilityConfidentialityProcessing IntegrityPrivacy
SideBlend follows SOC 2 standards. Enterprise customers may request our security documentation.
Request Security Docs
How We Protect You

Security at every layer

From how we handle your OAuth tokens to how AI requests are made, security is built into every part of SideBlend.

🔐

OAuth 2.0 Authentication

We connect to Salesforce, HubSpot, and Google via OAuth 2.0. We never store your CRM username or password — only short-lived access tokens that you can revoke at any time.

🛡️

Encrypted in Transit

All communication between the extension and external services (CRM APIs, AI providers, Google) uses TLS 1.2 or higher. No data travels unencrypted.

📦

Local-First Architecture

SideBlend runs as a Chrome extension. Your CRM data is fetched directly from your CRM to your browser — it does not route through our servers or get stored in our databases.

🤖

Bring Your Own API Keys

AI API keys (Claude, OpenAI, Gemini) are stored locally in your browser’s encrypted extension storage. We never transmit or log your API keys.

👁️

Minimal Permissions

SideBlend requests only the CRM and Google permissions it needs to function. We follow the principle of least privilege — no broad admin access, no unnecessary scopes.

🔄

Revoke Access Anytime

You can disconnect SideBlend from your CRM, Google Workspace, or AI provider at any time from the Settings screen. Revoking access immediately ends all data access.

Found a vulnerability?

We take security reports seriously. If you discover a potential security issue in SideBlend, please contact us directly. We commit to acknowledging your report within 48 hours and working with you to resolve it responsibly.

📧 Report a Security Issue
01
Submit your report
Email security@sideblend.com with details of the issue, steps to reproduce, and potential impact.
02
We acknowledge within 48h
Our team reviews every report and confirms receipt. We keep you updated throughout the resolution process.
03
We patch and credit
Once resolved, we issue a fix and optionally credit you in our security acknowledgements.