Security & Compliance

Enterprise security. Built into every layer.

From environment isolation to role-based access and IP restrictions — encatch is built for teams where security is not optional.

  • Sandbox isolation with a controlled hand-off to production
  • Roles, domain controls, IP restrictions, and enterprise SSO
  • Scoped API keys with HMAC identity signing

Security layers

Controls overview

Access Control

Domain locking

IP whitelisting

Role-based permissions

Environments

Sandbox isolation

Template hand-off to production

No dev access to prod

API Keys

Domain-scoped

Env-scoped + expiry

Data Governance

Configurable retention

Access log (Enterprise)

Capabilities

Security at every layer of the stack.

From sandbox isolation to enterprise SSO — encatch gives IT admins and security teams the controls they need, without slowing down the product team.

Sandbox environment

Isolated project type for safe integration, testing, and PM review — no production usage charged.

Template hand-off

Download a tested form as a template and upload it into another project, even when the two teams don't share access to a common project. Developers never need production access.

Custom roles

Define roles at org and project level — feedback manager, integration manager, system admin, and more.

Domain locking

Prevent unauthorized users on your domain from signing up to the admin portal.

IP whitelisting

Restrict admin portal access to trusted IP addresses and corporate networks.

SSO (OIDC / SAML)

Enterprise single sign-on integration with your identity provider — OIDC and SAML supported.

API key scoping

Keys scoped to specific domains, environments (sandbox/production), and permission types.

Access log (Enterprise)

See who accessed your admin portal and when.

Configurable retention

Set your data retention window from 30 days up to 3 years, depending on your plan. Records are purged automatically.

Sandbox rate limits

Lower rate limits in sandbox protect the platform while giving enough capacity for testing.

Key expiry controls

Keys scoped to specific domains, environments (sandbox/production), and expiry dates — no stale credentials.

HMAC identity signing

Server-side HMAC-SHA256 signatures verify every user identity call. Time-bound validity windows prevent replay attacks and protect MAU billing integrity.

Sandbox environment

Ship feedback safely. No production access required.

In most tools, configuring feedback requires developers and PMs to work in production — which means either giving developers production access, or constant back-and-forth coordination. encatch Sandbox breaks that model entirely. PMs configure forms, triggers, and screen paths in a fully isolated environment. Developers implement SDK events there. Once everything is validated together, the PM hands the form to production as a template — no developer ever touches it.

PMs configure feedback experiences in Sandbox without developer involvement in production
Developers implement SDK events and URL paths in Sandbox only — no production credentials needed
PM reviews the full end-to-end flow in Sandbox before a single line ships to users
Move a tested form into Production as a template, so the PM controls what ships
Sandbox activity does not consume production MAU, response, or destination quotas
Use Sandbox for ongoing validation — new forms, events, and experience changes, continuously

Sandbox

Safe to iterate

Production

PM-controlled

How teams work together

PM

Configures feedback forms, triggers, and screen paths in Sandbox

Dev

Implements SDK events and URL paths in Sandbox — no production access needed

PM

Reviews end-to-end in Sandbox. Approves and moves the form to Production as a template

Prod

Production config goes live — developers never touched it

Sandbox usage does not count against production quotas

Security controls

Control access. Protect every identity.

Connect organization permissions, scoped credentials, and server-side identity signing.

The right people see the right things — nothing more.

encatch's role system gives you surgical control over who can do what. Roles are defined at the organization level or scoped to individual projects — so your integration manager can manage webhooks without seeing feedback responses, and your feedback manager can analyze responses without touching API keys or billing.

  • Custom roles at both organization and project level — no one-size-fits-all permissions
  • Org Admin role is immutable and always protected — cannot be deleted or modified
  • Domain locking prevents unauthorized signups on your corporate domain
  • IP whitelisting restricts admin portal access to your office or VPN networks
  • SSO via OIDC or SAML for enterprise identity provider integration

Custom roles

Org Admin

Organization level

Immutable
Manage membersManage rolesAll projects

Feedback Manager

Project level

View responsesManage formsExport data

Integration Manager

Project level

Manage destinationsManage API keysView pipeline

Admin portal controls

Domain locking

Prevent unauthorized signups on your domain

IP whitelisting

Restrict admin access to trusted networks only

SSO (OIDC / SAML)

Enterprise identity provider integration

Data governance

Your data, your way.

encatch gives compliance teams the controls they need: configurable retention windows, automated data purging, user deletion or anonymization, and an access log on Enterprise that shows who accessed your admin portal and when.

Retention from 30 days up to 3 years, depending on your plan
Automated purging — data older than your retention window is removed automatically
Access log on Enterprise shows who accessed your admin portal
Coming soon: daily export to S3 or a webhook before the retention window closes

Data governance

Data retention

Retention window

Up to 3 years
3 months (Free)3 years (Team, Growth)

Access log · Enterprise

admin@acme.com · portal_access · Admin portal

2h ago

dev@acme.com · portal_access · Admin portal

5h ago

pm@acme.com · portal_access · Admin portal

1d ago

Product journey

Keep following the signal.

A little more detail

Security & Compliance, answered

Common questions about sandboxing, access control, and data governance in encatch.

Does encatch keep a log of admin access?

Yes. On Enterprise plans, the access log shows who accessed your admin portal and when, which supports enterprise security reviews.

Which feedback software have sandbox environments?

Encatch has separate Sandbox and Production projects on Team and above. Developers integrate and test in a Sandbox project, where usage doesn't count toward your plan. Once a form is ready, you hand its design to Production as a template: download it as JSON and upload it into My saved templates, which works even when the two teams don't share access to a common project.

What is the best feedback software suitable for healthcare or financial services teams?

Encatch includes the infrastructure controls regulated industries typically ask for: field-level capture settings, a consent-aware SDK mode, HMAC identity signing, role-based access, API keys scoped per environment, and on Enterprise, SSO, access logs, and private or your own cloud hosting. Teams in financial services, healthcare, or insurance should contact Encatch to discuss specific compliance requirements.

Is Encatch GDPR compliant?

Encatch includes the core technical controls for GDPR-compliant data handling: field-level capture settings to leave personal data out, a consent-aware SDK mode, HMAC identity signing, user deletion or anonymization, and configurable retention. Our Data Processing Addendum is published in the legal docs.

Does Encatch support SSO?

Yes. Encatch supports Single Sign-On via OIDC and SAML, allowing enterprise teams to connect their existing identity providers. SSO is available on Enterprise plans.

Enterprise ready

Security that works for your team — not against it.

Sandbox environments, granular roles, and API key scoping mean your team ships faster without compromising control. Talk to us about enterprise deployment options.