> ## Documentation Index
> Fetch the complete documentation index at: https://docs.poodleailabs.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Security Practices

> Authentication, encryption, infrastructure, and audit logging in Poodle AI.

## Authentication and access control

* Sign-in is handled through Auth0, an industry-standard identity provider, rather than Poodle AI storing plaintext credentials directly.
* Access to an organization's data is scoped by role: **Rep**, **Admin**, and **Super Admin**, each with progressively broader permissions (for example, only Admins can connect a CRM, change company settings, or manage billing).
* New members join an organization only through an admin-issued invitation or an approved sign-up flow — there is no open self-serve join into an existing organization's data.

## Encryption

* CRM integration credentials (OAuth access and refresh tokens for Salesforce, HubSpot, Zoho CRM, Outreach, and Gong) are encrypted before they are stored, using authenticated symmetric encryption with a dedicated encryption key. They are decrypted only in memory, at the moment they're needed to call the provider's API.
* Product traffic is served over HTTPS/TLS.
* Uploaded files and session recordings are stored in Amazon S3 and accessed only through short-lived, pre-signed URLs rather than public links.

## Infrastructure

* Poodle AI is hosted on Amazon Web Services (AWS), using a managed PostgreSQL database and S3 for file and recording storage.
* Live practice sessions run on LiveKit's real-time media infrastructure.
* CRM synchronization jobs run as isolated AWS Lambda functions rather than inside the main application.

## Monitoring and audit logging

* Every CRM connection event (connect, disconnect, consent grant/revoke, data access, data deletion) is written to an access log with a success or failure status, scoped to the organization.
* Changes to a user's privacy consent preferences are written to a separate audit log, capturing the previous and new state, how consent was collected, and a hashed IP address — accessible only to Super Admins for compliance review.
* Per-provider rate limiting is enforced on CRM API calls to prevent abuse and protect connected third-party systems.

<Note>
  Details governed by internal policy rather than product configuration — including penetration testing cadence, vulnerability management SLAs, and personnel security training — are available on request from your account team.
</Note>

<Card title="Next: your data privacy rights" icon="user-shield" href="/trust-center/data-privacy-and-your-rights">
  How consent, data export, and deletion work.
</Card>
