SECURITY

Your records, your mailbox, your calls: yours alone

Only your workspace can reach your records, only the people you choose can open a thread or a call, every AI value waits for your approval, and you can take your data with you.

Last updated: 5 September 2026

Only your workspace can reach your records

Every record, value, view, list, email, call and automation belongs to one workspace, and only members of that workspace can reach it. The rule is enforced in the database itself, so it holds for every connection, including ours. Inside it, four roles from owner to viewer decide what each member can do, and ownership moves only when the current owner confirms the new owner by name.

Your mailbox and calls stay yours

Gmail and Outlook connect through the provider's own sign-in screen. Ishara never asks for, sees or stores a mailbox password. Removing a mailbox takes everything synced from it with it, so nothing from a disconnected account lingers. Every email thread and every call carries its own visibility: only me, the people on it, my team, or everyone in the workspace.

Consent that holds, AI you approve

When someone opts out, they stay out. An unsubscribe stops marketing sends and sequence steps, and a bounce or a complaint stops everything to that address. The record of what a person refused outlives the rest of their data, so a refused message never starts again, in line with the Saudi Personal Data Protection Law and similar regional laws. AI you approve before it writes anything: a suggestion waits until a person accepts it, every accepted value stays tagged as AI, and a model sees only the declared fields of the record it is asked about, never your mailbox, your files or the rest of the workspace. Details on the email page and the AI page.

Backup, portability and hosting

Every change can be undone and traced back to who made it. Archived records stay restorable, you set your own retention window, and deletion always asks you to confirm the count. Every view exports to CSV, and a full workspace backup exports as JSON or XLSX and restores into a fresh pipeline. Leaving costs nothing: the workspace reverts to Free and nothing is deleted. API keys and webhook secrets are shown once and can be rotated any time, and every webhook delivery is signed, so a receiver can reject a replay; the developers page has the details.

Ishara is hosted on Supabase Postgres. Sub-processors: Supabase, the mailbox provider you connect, MeetriX for call recordings, Logo.dev and Brandfetch for marks, and AI model providers under your workspace policy. Hosting region on request at support@lisan.com. Security questions and vulnerability reports go to the same address. To see all of this on screen, book a walkthrough.

Frequently asked questions

Where is the Ishara data hosted?

On Supabase Postgres with row-level security enabled and forced on every table that holds workspace data. The sub-processor list is on this page under Backup, portability and hosting, and the hosting region is stated on request at support@lisan.com.

Can a teammate read my mailbox?

Only what the visibility policy on each thread allows: Only me, people on this thread, my team, or everyone. Connecting a mailbox does not open it to the workspace, and delegated read access is something you grant explicitly, per account.

Does Ishara sell personal data?

No. We do not sell personal data, and we do not use workspace content for advertising. Your records, email and calls are processed only to run the service for you.

Questions about data handling? Ask us.

32,822 investors, government tenders across six markets and a CRM that starts free. Bring your data from any CRM or spreadsheet in an afternoon.

Free plan · 32,822 investors · six markets