Private client workspaces
Client and campaign access checks limit users to the information they are permitted to view. Smittinn administrators manage the service across authorized workspaces.
Breakthrough OS
Breakthrough OS is designed for private campaign operations, with access limited to authorized users and information separated by client and campaign permissions.
Client and campaign access checks limit users to the information they are permitted to view. Smittinn administrators manage the service across authorized workspaces.
Administrative and client roles control access to management functions, campaign records, imports, exports, audit information, and other restricted actions.
There is no unrestricted public account registration. Client access is established through controlled, expiring, single-use invitations.
Passwords are processed with a salted password-derivation function and are not stored as readable plaintext.
Session identifiers are stored in hashed form. Browser cookies are HttpOnly and SameSite restricted, use the Secure attribute over HTTPS, and authenticated changes require request-verification tokens.
Important administrative and campaign actions can be recorded with an actor, time, action, and affected record to support accountability.
Public tracking URLs use opaque tokens. The public redirect does not include a contact name, email address, internal database identifier, password, session value, API credential, or the stored token itself. Scan records are limited to operational details such as time, device category, a reduced referrer origin, and a hashed request fingerprint used to reduce duplicate activity.
Public forms should request only information needed for the applicable inquiry, campaign, or service. Private CRM notes, another recipient's information, internal identifiers, authentication data, API credentials, and secret tracking tokens are not intended for public pages.
Breakthrough OS is hosted using Cloudflare Pages, Functions, and D1 database infrastructure. The public service is delivered over HTTPS, which protects information while it travels between a supported browser and the service. Cloudflare's role does not mean Breakthrough OS holds certifications that have not been independently obtained and verified.
Security also depends on careful account administration, strong unique passwords, authorized data use, and appropriate handling of exported information. No online service can eliminate every risk.
Questions or suspected account misuse can be reported to info@smittinn.com.