Built to protect what you connect
Skrivox holds real credentials for your connected platforms and handles your billing relationship with Stripe. Here is what that actually means for how your data is stored and accessed.
See how it works ↓What protects your data
Passwords are never stored in plain text
Skrivox hashes every password with scrypt and a unique per-user salt before it ever touches the database. Nobody at Skrivox, including us, can read your password back. A lost or reset password is the only way in if you forget it.
Connected-platform credentials are encrypted at rest
When you connect Meta, TikTok, Google Analytics, Google Search Console, Canva, or an external MCP server, the access tokens and API keys we store for that connection are encrypted with AES-256-GCM before they reach the database, not stored as plain text alongside your other workspace data.
Sessions are locked down at the cookie level
Your sign-in session is an HttpOnly, Secure, SameSite cookie. It cannot be read by page scripts, is never sent over plain HTTP, and is not attached to ordinary cross-site requests.
Payment details never touch our servers
Card numbers go directly to Stripe. Skrivox never receives, stores, or sees your raw card details. Billing events we do receive from Stripe are cryptographically signed, and we verify that signature before acting on any of them.
Every request is scoped to your workspace
Data access is checked against your workspace and your role on it (owner or member) on every request. There is no cross-workspace query path that a bug in one workspace’s data could fall through into another’s.
Beyond storage
- Outbound requests are checked first
- Any URL Skriv is asked to reach out to, whether it's a landing page's call-to-action link or an external MCP server you've connected, is resolved and checked against private and reserved network ranges before Skrivox connects to it.
- Sign-in attempts are rate-limited
- Login, password reset, and other public-facing endpoints limit how often they can be called from a given source, so they cannot be used as an open door for automated guessing.
Skrivox is a growing product, not a certified enterprise platform. We don't hold a SOC 2 or ISO 27001 certification today, and we don't want to claim one we don't have. What's above is what's actually built and true right now.
Found a security issue?
Tell us directly at hello@skrivox.com rather than filing a public issue. We'll follow up.
Start freeView pricing