Security

Control is part of the product.

GridHand is designed around tenant isolation, narrow workflows, and explicit human approval—not broad automation.

Owner-scoped access

Every business record is tied to a tenant. Authenticated owners can only reach the business profile and workflow data assigned to them.

Approval before outreach

Missed-call and review-request messages enter a pending queue. The send path fails closed unless a one-time owner approval can be verified.

Server-side credentials

Privileged database and messaging credentials stay on the server. They are initialized only inside the request or command that needs them.

Controlled pilot boundaries

The pilot does not activate billing, ads, social posting, autonomous agents, voice answering, or customer outreach outside the reviewed workflows.

Report a security concern

Send the affected page, what you observed, and a safe way to reach you. Do not include passwords, API keys, or customer data.

security@gridhand.ai