Security
How Pontem Sales protects your deals and your buyers' information, and what we do not claim. Last updated October 6, 2026.
How workspaces are kept apart
Every customer has its own workspace, and the database enforces that one workspace cannot read or change another's. This is done at the database level, not only in the screens, so it holds however the data is requested. Inside a workspace, owners and admins control who is on the team and what role each person has. Some pages, such as the reports and the team list, are limited to owners and admins.
Internal and buyer-facing information
- PontemVelo plans are internal. They are never shared with a buyer.
- Deal details and buyer notes inside a PontemClient plan are internal. A buyer sees only the shared plan and can only change the steps assigned to their side.
- A buyer link is a private link made for one person. It expires, and an owner or admin can turn it off at any time.
Sign-in and passwords
Sign-in and passwords are handled by our authentication provider, so passwords are not stored in our own tables. People join a workspace through a one-time invitation link that expires.
Payments
Card payments are taken by Stripe on its own secure page. Card numbers never pass through or are stored by Pontem Sales. A workspace is only created after Stripe confirms the payment.
Email and calendar link
When a customer links Microsoft 365, access is read-only and limited to counts and attendee details: when mail was sent and to whom, whether there was a reply, and calendar invitations with outside attendees. Pontem Sales does not read subjects, message text, attachments, or the titles and notes of calendar events. Each person, or a Microsoft 365 administrator, can disconnect it at any time.
Data in transit and providers
The website and the app are served over HTTPS. We use established providers for hosting and the database (Supabase), payments (Stripe) and email (Resend), and rely on their security controls. Our Privacy Policy lists who they are and what they handle.
Our own access
Access to the administration side of Pontem Sales is limited to Pontem staff who need it. Pontem-wide statistics are built only from anonymised, aggregated data and are produced only when at least three workspaces are included. See the Privacy Policy for details, and how to leave a workspace out.
What we do not claim
We do not currently hold a SOC 2 or ISO 27001 certification. If your organization needs a security questionnaire or a conversation with our team as part of buying, tell us. Enterprise plans include security review support.
Reporting a problem
If you believe you have found a security issue, or that your account may have been compromised, email [email protected] with the subject "Security". Please give us reasonable time to fix a problem before sharing it publicly. We will acknowledge your message and keep you informed.