Breakthrough OS

Security & Privacy

Breakthrough OS is designed for private campaign operations, with access limited to authorized users and information separated by client and campaign permissions.

Private client workspaces

Client and campaign access checks limit users to the information they are permitted to view. Smittinn administrators manage the service across authorized workspaces.

Role-based access

Administrative and client roles control access to management functions, campaign records, imports, exports, audit information, and other restricted actions.

Invitation-only accounts

There is no unrestricted public account registration. Client access is established through controlled, expiring, single-use invitations.

Password protection

Passwords are processed with a salted password-derivation function and are not stored as readable plaintext.

Secure sessions

Session identifiers are stored in hashed form. Browser cookies are HttpOnly and SameSite restricted, use the Secure attribute over HTTPS, and authenticated changes require request-verification tokens.

Activity and audit history

Important administrative and campaign actions can be recorded with an actor, time, action, and affected record to support accountability.

Safe campaign tracking

Public tracking URLs use opaque tokens. The public redirect does not include a contact name, email address, internal database identifier, password, session value, API credential, or the stored token itself. Scan records are limited to operational details such as time, device category, a reduced referrer origin, and a hashed request fingerprint used to reduce duplicate activity.

Forms and data minimization

Public forms should request only information needed for the applicable inquiry, campaign, or service. Private CRM notes, another recipient's information, internal identifiers, authentication data, API credentials, and secret tracking tokens are not intended for public pages.

Cloudflare infrastructure

Breakthrough OS is hosted using Cloudflare Pages, Functions, and D1 database infrastructure. The public service is delivered over HTTPS, which protects information while it travels between a supported browser and the service. Cloudflare's role does not mean Breakthrough OS holds certifications that have not been independently obtained and verified.

Shared responsibility

Security also depends on careful account administration, strong unique passwords, authorized data use, and appropriate handling of exported information. No online service can eliminate every risk.

Questions or suspected account misuse can be reported to info@smittinn.com.