Security & privacy
Access stays within the right boundary.
Slotkit keeps account sign-in, booking-page access, and server-side API access separate so one credential cannot silently replace another.
Core controls
- Every request rechecks which workspace and resources the user or API Key may access.
- One-time login and verification credentials are stored as hashes; provider credentials are encrypted.
- Webhook destinations are checked to prevent delivery to private or unsafe network addresses.
- Guest personal data follows a fixed 24-month retention period; short-lived access credentials are removed sooner.
- Workspace deletion includes a 30-day grace period and tracks required Calendar and Webhook cleanup.
Operational logs and metrics use safe identifiers instead of guest email addresses, booking Metadata, tokens, or secrets.