Data Confidentiality
Last updated 1 September 2026
Agents put their entire book into Pipeflow. Principals put an entire brokerage into it. This page explains, plainly, how the two coexist.
Permissions live in the database
Most systems hide what you should not see by not drawing the button. Pipeflow decides at the data layer: 75 row-level security policies across 31 tables. A request for a record outside your reach does not return a locked door — it returns nothing, because nothing matched.
Who sees what
- An agent sees their own contacts, deals, listings, tasks and commission.
- A team lead sees their own book plus the agents on their team, and nothing from another team.
- A principal sees the brokerage: every agent, every deal, every dollar of gross commission.
- An assistant sees only what the agent they support has granted.
Mailbox content
A connected mailbox belongs to the person who connected it. Colleagues, team leads and principals never read your mail. What can become visible to others is the CRM record created from it — a deal, a contact, a date — and only within the visibility rules above.
Voice input
Voice is transcribed to interpret an instruction and produce a proposed change. Proposals are yours until you accept them. Auto-apply is off by default, requires two separate opt-ins, and still leaves an undo window on every change.
When someone leaves
Ending a person's access ends it immediately and everywhere. Records that belong to the brokerage stay with the brokerage; records that belong to the agent stay with the agent, per your brokerage agreement.
Security practices
- Data encrypted in transit and at rest.
- Access to production limited to staff who need it, with audited entry.
- Backups taken regularly and tested for restore.
- Third-party processors bound by contract to the same confidentiality standard.
Reporting a concern
If you believe data has been exposed or a permission is behaving incorrectly, write to support@pipeflowhub.com and mark it urgent. We investigate security reports first.