Security by design
Enterprise-minded controls for every product line
Whether you sync Gmail, Microsoft mail, calendar, files, or Notion, you share one hardened platform: authenticated APIs, user-scoped data access, secret-gated automation, and recurring automated scans — operated by Saaniya Software LLC.
Inbox, Today, Sync Health, and AI briefing sit on the same authenticated, user-scoped stack as Settings and provider connections.
Shared platform baseline
Security controls are platform features — not a separate add-on. Continuous scanning and hardening apply across this product line.
User-scoped APIsAuth.js sessionsServer-side OAuthSemgrep + audit CISecret-gated crons
Account isolation
Auth.js sessions plus optional Turnstile on auth paths — every sync and API path scopes data to the signed-in user.
Guarded integrations
OAuth connections you can revoke in Settings, explicit scopes, and tokens that never leave the server. Crons and webhooks fail closed without secrets.
Continuous scanning
Semgrep SAST on every push to development/main, weekly npm audit + build checks, and optional OWASP ZAP baseline on Preview before big ships.
Platform ops
Superadmin operator tools for diagnostics and support — without reading your mailbox contents as a default path.
These measures reduce risk; they do not guarantee absolute security or certify your workflow for a specific regulation. See the Disclaimer for limits of liability.