Sandbox environment
Isolated project type for safe integration, testing, and PM review — no production usage charged.
Security & Compliance
From environment isolation to role-based access and IP restrictions — encatch is built for teams where security is not optional.
Security layers
Access Control
Domain locking
IP whitelisting
Role-based permissions
Environments
Sandbox isolation
Template hand-off to production
No dev access to prod
API Keys
Domain-scoped
Env-scoped + expiry
Data Governance
Configurable retention
Access log (Enterprise)
Capabilities
From sandbox isolation to enterprise SSO — encatch gives IT admins and security teams the controls they need, without slowing down the product team.
Isolated project type for safe integration, testing, and PM review — no production usage charged.
Download a tested form as a template and upload it into another project, even when the two teams don't share access to a common project. Developers never need production access.
Define roles at org and project level — feedback manager, integration manager, system admin, and more.
Prevent unauthorized users on your domain from signing up to the admin portal.
Restrict admin portal access to trusted IP addresses and corporate networks.
Enterprise single sign-on integration with your identity provider — OIDC and SAML supported.
Keys scoped to specific domains, environments (sandbox/production), and permission types.
See who accessed your admin portal and when.
Set your data retention window from 30 days up to 3 years, depending on your plan. Records are purged automatically.
Lower rate limits in sandbox protect the platform while giving enough capacity for testing.
Keys scoped to specific domains, environments (sandbox/production), and expiry dates — no stale credentials.
Server-side HMAC-SHA256 signatures verify every user identity call. Time-bound validity windows prevent replay attacks and protect MAU billing integrity.
Sandbox environment
In most tools, configuring feedback requires developers and PMs to work in production — which means either giving developers production access, or constant back-and-forth coordination. encatch Sandbox breaks that model entirely. PMs configure forms, triggers, and screen paths in a fully isolated environment. Developers implement SDK events there. Once everything is validated together, the PM hands the form to production as a template — no developer ever touches it.
Sandbox
Safe to iterate
Production
PM-controlled
How teams work together
Configures feedback forms, triggers, and screen paths in Sandbox
Implements SDK events and URL paths in Sandbox — no production access needed
Reviews end-to-end in Sandbox. Approves and moves the form to Production as a template
Production config goes live — developers never touched it
Sandbox usage does not count against production quotas
Security controls
Connect organization permissions, scoped credentials, and server-side identity signing.
encatch's role system gives you surgical control over who can do what. Roles are defined at the organization level or scoped to individual projects — so your integration manager can manage webhooks without seeing feedback responses, and your feedback manager can analyze responses without touching API keys or billing.
Custom roles
Org Admin
Organization level
Feedback Manager
Project level
Integration Manager
Project level
Admin portal controls
Domain locking
Prevent unauthorized signups on your domain
IP whitelisting
Restrict admin access to trusted networks only
SSO (OIDC / SAML)
Enterprise identity provider integration
Data governance
encatch gives compliance teams the controls they need: configurable retention windows, automated data purging, user deletion or anonymization, and an access log on Enterprise that shows who accessed your admin portal and when.
Data governance
Data retention
Retention window
Up to 3 yearsAccess log · Enterprise
admin@acme.com · portal_access · Admin portal
2h agodev@acme.com · portal_access · Admin portal
5h agopm@acme.com · portal_access · Admin portal
1d agoProduct journey
A little more detail
Common questions about sandboxing, access control, and data governance in encatch.
Yes. On Enterprise plans, the access log shows who accessed your admin portal and when, which supports enterprise security reviews.
Encatch has separate Sandbox and Production projects on Team and above. Developers integrate and test in a Sandbox project, where usage doesn't count toward your plan. Once a form is ready, you hand its design to Production as a template: download it as JSON and upload it into My saved templates, which works even when the two teams don't share access to a common project.
Encatch includes the infrastructure controls regulated industries typically ask for: field-level capture settings, a consent-aware SDK mode, HMAC identity signing, role-based access, API keys scoped per environment, and on Enterprise, SSO, access logs, and private or your own cloud hosting. Teams in financial services, healthcare, or insurance should contact Encatch to discuss specific compliance requirements.
Encatch includes the core technical controls for GDPR-compliant data handling: field-level capture settings to leave personal data out, a consent-aware SDK mode, HMAC identity signing, user deletion or anonymization, and configurable retention. Our Data Processing Addendum is published in the legal docs.
Yes. Encatch supports Single Sign-On via OIDC and SAML, allowing enterprise teams to connect their existing identity providers. SSO is available on Enterprise plans.
Enterprise ready
Sandbox environments, granular roles, and API key scoping mean your team ships faster without compromising control. Talk to us about enterprise deployment options.