Data & Security
How Feather protects your information and respects your ownership.
Security and privacy are not afterthoughts at Feather — they're built into how the product works. This page outlines our security practices, data handling commitments, and what you can do to keep your account safe.
Last updated: March 4, 2025
Data encrypted in transit
TLS / HTTPS everywhere
Data encrypted at rest
Stored data is protected
No data selling
Your data is never sold
Data Ownership
Your data belongs to you — fully and completely. Everything you create inside Feather — your contacts, notes, pipelines, records, and files — is yours.
- We do not use your data for advertising
- We do not sell your data to third parties
- We do not mine your content for training models or other purposes
- We process your data only to operate and deliver the service to you
You can export all of your data at any time from within the application, in standard formats (CSV, JSON). If you close your account, your data will be permanently deleted within 30 days.
Encryption
Feather uses industry-standard encryption to protect data in motion and at rest.
- In transit: All communication between your browser and our servers is encrypted using TLS (Transport Layer Security) / HTTPS. Plain HTTP connections are not permitted.
- At rest: Data stored in our databases and file storage systems is encrypted at rest using AES-256 or equivalent.
- Authentication tokens: Session tokens are signed and time-limited to reduce exposure from token theft.
Access Controls
Access to customer data is tightly controlled at every level:
- Production systems are isolated and not directly accessible to general staff
- Access to databases and infrastructure is restricted to a minimal set of authorized systems and personnel
- All internal access is logged and monitored
- Administrative access requires multi-factor authentication
We follow a principle of least privilege: systems and people only have access to what they absolutely need to perform their function.
Infrastructure & Reliability
Feather is built on secure, modern cloud infrastructure designed for reliability, scalability, and protection.
- Hosted on reputable, enterprise-grade cloud providers with strong security certifications
- Automated backups are taken regularly to protect against data loss
- Infrastructure is monitored continuously for availability and anomalies
- We apply security patches and updates promptly
Incident Response
In the event of a security incident, we have procedures in place to:
- Contain and investigate the incident promptly
- Notify affected users as required by applicable law
- Take corrective action to prevent recurrence
- Cooperate with relevant authorities where appropriate
Responsible Disclosure
We take security reports seriously. If you discover a potential vulnerability in Feather, we encourage you to report it responsibly before making it public.
Please send vulnerability reports to: security@feather-crm.com
Please include a clear description of the issue, steps to reproduce it, and any proof-of-concept if available. We will acknowledge your report within 72 hours and keep you updated on our progress.
Your Responsibility
Security is a shared responsibility. To help keep your account secure, we recommend:
- Use a strong, unique password for your Feather account
- Do not share your login credentials with others
- Log out of your account on shared or public devices
- Be cautious of phishing emails impersonating Feather — we will never ask for your password by email
- Contact us immediately at support@feather-crm.com if you suspect unauthorized access
Contact
For general security questions or to report a concern:
Feather Security
General: support@feather-crm.com
Vulnerabilities: security@feather-crm.com
Website: feather-crm.com
