1. Multi-tenant data isolation
LiftUp is multi-tenant. Each customer is an organisation, and every record it owns carries that organisation's ID. The application adds the ID to every database query through a global scope. It is not a filter in the interface that a user can remove.
Inside your organisation, each website or app is a product with its own rotatable API key, lead inbox, blog, custom fields and webhooks. Products share your team, your roles and your bill.
2. Hashed API keys and signed webhooks
- API keys are hashed before they are stored. You see a key once, when you create it, and you can rotate it per product.
- Webhook payloads are signed with HMAC SHA-256, so your endpoint can check that a request came from LiftUp.
3. Sign-in: 2FA and Google SSO
- Two-factor authentication with time-based codes (TOTP) from any authenticator app.
- Enterprise admins can enforce 2FA for everyone in the organisation.
- Sign in with Google on Enterprise.
- SAML and Microsoft sign-in are not available.
4. Role-based access control
Each user in your organisation gets one built-in role. The role decides which modules a person can open and whether they can change anything.
- Admin: full control of the organisation.
- Operations Manager: CRM, content and settings.
- Sales Manager: leads, pipeline and assignments.
- Content Manager: blog, editorial workflow and AI writing.
- HR Manager: career and hire inboxes, and candidates.
- Read Only: dashboards and reports, with no changes.
Global search (Ctrl/Cmd + K) applies the same permissions, so it never returns a record your role cannot open.
5. Audit log
LiftUp records changes to leads, blog posts, products, staff accounts and organisation settings in an audit log. You see it as an activity feed on the dashboard.
The audit log is included on Growth and Enterprise. Enterprise keeps a longer history.
Webhooks have their own delivery log, so you can see what LiftUp sent to your systems and whether it arrived.
6. Access by LiftUp staff
A small number of LiftUp operators hold a platform-admin role that can see across organisations. We use it to run the service and answer support requests.
Email [email protected] if your review needs our staff-access policy.
7. Hosting and backups
- LiftUp is a hosted service. There is nothing to install.
- Traffic reaches the app through Cloudflare.
Ask us for hosting and backup details during a demo.
8. AI features and your data
When you use Content AI or Image AI, the text or prompt you submit is sent to our AI provider to generate the result. The style analyzer reads your published posts to learn your brand voice.
AI usage is metered per organisation and shown on a usage dashboard.
9. Data export
- Every plan can export leads as CSV.
- Enterprise can export the full organisation dataset at any time.
10. Payments
Payments in USD and INR go through Razorpay, including UPI AutoPay for INR.
11. GDPR, DPDP and certifications
Our Privacy Policy explains that LiftUp acts as your processor for lead data you store. It also lists the kinds of processors we use.
LiftUp does not hold a SOC 2 report or an ISO 27001 certificate today.
Enterprise customers can ask us to sign a data-processing agreement.
12. Report a vulnerability
If you think you have found a security issue, email [email protected] with a description and steps to reproduce.
Give us reasonable time to fix the issue before you disclose it, and do not access or change data that is not yours.
Questions about security in general go to the same address: [email protected].