Built to look, not to touch
RimeGuard asks for as little access as the job allows, keeps as little data as it can, and never changes anything without your approval. Here's exactly how.
Reads, never writes
RimeGuard reads your setup. It has no code that edits your records or your workflows.
You approve every fix
Nothing is changed or deployed until you've seen the change and said yes.
Encrypted
Data travels over HTTPS. HubSpot access tokens are encrypted at rest with AES-256-GCM.
Kept briefly
Workflow code is read during each scan and not kept afterward, apart from the lines your report points to.
No AI training
Your data is never used to train AI models, ours or anyone else's.
Gone when you leave
Disconnecting deletes your access tokens and saved data right away.
The access we ask for
You approve these on HubSpot's own page when you connect, and you can remove them at any time in HubSpot's settings.
| What RimeGuard reads | Why |
|---|---|
| Your workflows, including the code inside custom code steps | To find code and steps that are broken or at risk |
| Contact, company and deal properties and their dropdown options | To check the code uses properties and values that still exist |
| Pipelines, stages and owners | To catch workflows pointing at things that were deleted or deactivated |
| Counts and dates from your records | To notice when a workflow quietly stops working, like new leads with no owner |
One honest note. Every permission RimeGuard asks for is read-only except one. HubSpot doesn't offer a read-only permission for workflows, so the "automation" permission technically allows editing them too. RimeGuard only ever reads with it, and the app contains no code that writes to your workflows.
How your data is handled
| Data | How long we keep it |
|---|---|
| HubSpot access tokens | Encrypted at rest. Deleted the moment you disconnect. |
| Workflow definitions and code | Read during each scan. Not stored afterward, apart from the lines quoted in your report. |
| Your reports | Until you disconnect, or 30 days, whichever comes first. |
| Monitoring history | The last 30 daily readings. Deleted when you disconnect. |
| Server logs | 30 days. |
We don't sell data, and we don't use advertising or analytics trackers. The full details are in our privacy policy.
How AI is used
When something breaks, RimeGuard can draft a suggested fix using Anthropic's Claude models. Only the affected code and the error details are sent, and passwords, tokens and keys we detect are removed first. Under Anthropic's commercial terms, that data isn't used to train their models.
An AI-drafted fix can be wrong. That's why every one is shown to you as a line-by-line change, tested where possible, and never applied until you approve it.
Running code safely
If we host a script for you, each run happens in its own locked-down container:
- No network by default. Internet access is switched on only for scripts that need it, such as ones that call HubSpot.
- Read-only and short-lived. The container can't change its own files and is thrown away after each run.
- No extra privileges. Scripts run as a restricted user, with memory, CPU and process limits.
- Only the credentials it needs. A script sees only the secrets you've assigned to it, never ours or another customer's.
Who has access
RimeGuard is run by one founder, who is the only person with access to production systems. Every account involved, including hosting, email and code, is protected with two-factor authentication. If that ever changes, this page will say so.
We're early, and we'll be straight with you
RimeGuard doesn't have a SOC 2 report yet. If your security team has a questionnaire, send it to us. We'll answer every question honestly, including the ones where the answer is "not yet."
Report a security issue
If you think you've found a vulnerability in RimeGuard, email security@rimeguard.com. Please include enough detail for us to reproduce it, and give us a reasonable chance to fix it before sharing it publicly. We'll reply within two business days and keep you updated until it's resolved.