Security and data handling

Legacy Bridge performs your integration’s calls in memory and keeps only what it needs to run: no CRM records, ever.

What the bridge stores

  • Your bridge: the e-mail you signed in with, your licence and plan, the name you give a portal; the licence key sealed with AES-256-GCM.
  • The access token of your portal, sealed with AES-256-GCM, and the portal id.
  • Bridge keys and console sessions as SHA-256 hashes only; a key is shown once.
  • Daily request counters, and coverage events with operation, status, reason and latency.
  • Short-lived metadata the translation needs: opaque HubSpot paging cursors (24 hours), property names and types (10 minutes), engagement types and the portal id (24 hours).

What it never stores

Contacts, companies, deals, tickets, property values and files. They pass through memory to answer the call. Logs carry no request URLs, so a hapikey never lands there, and a test in the code base fails if an event ever carries CRM content.

Scopes

The bridge can only do what the token you save allows. Give the app the scopes of the APIs your integration calls, nothing more; the connection guide has the list per API.

Where it runs

The hosted bridge runs on Cloudflare Workers and keeps its data in Cloudflare D1 and R2; daily database backups are deleted after 90 days. The self-hosted licence runs the same code as a Docker image on your server: then nothing but the daily licence check reaches us.

Who else handles data

Cloudflare (hosting), HubSpot (the calls your integration sends, for your portal only) and Paddle (payments). No analytics, no trackers, no third-party scripts on these pages except Paddle’s checkout. The full list is in the Privacy Policy.

Reporting a problem

Security issues go to support@avakode.com; we answer within two business days and faster for anything that affects customer data.