Security Best Practices
Protect your account, API keys, and data.API Key Security
Environment Variables
Never hardcode API keys:.gitignore
Ensure secrets aren’t committed:Key Rotation
Rotate keys regularly:Minimum Permissions
Only grant necessary permissions:Webhook Security
Always Verify Signatures
IP Allowlisting
Restrict webhook origins:Account Security
Enable Two-Factor Authentication
Require 2FA for all team members:Review Team Access
Regularly audit team members:Use SSO (Enterprise)
Enterprise customers should use SSO for centralized access management.Data Protection
Sensitive Data in Emails
Don’t include sensitive data in email content that’s logged:Metadata Security
Don’t store sensitive data in metadata:Monitoring
Set Up Alerts
Monitor for suspicious activity:Audit Logs
Review account activity:Security Checklist
1
API Keys in Environment Variables
Never hardcode keys in source code.
2
Minimum Permissions
Only grant permissions actually needed.
3
Webhook Signature Verification
Always verify webhook signatures.
4
Two-Factor Authentication
Enable 2FA for all team members.
5
Regular Key Rotation
Rotate API keys every 90 days.
6
Access Reviews
Audit team access quarterly.