Stage 1

Encrypted connection keys in Stage 1

The keys that connect Stage 1 to LinkedIn, email and Slack are encrypted at rest with AES-256-GCM and never shown again after you save them.

Kevin French
· 3 min read

The keys that connect a sales tool to your LinkedIn and your inbox are the keys to your name. Anyone holding them can write to your buyers as you. Stage 1 treats them that way, from the moment you paste one in.

What counts as a connection key

A connection key is anything that lets Stage 1 act on an outside account for you. The Unipile keys and account IDs that link your LinkedIn and email. The Slack webhook that posts to your channel. The token for an optional Apify account. The Meta access token and ad account ID for ad audiences. And the private tokens Stage 1 makes for each workspace, so replies and connection callbacks reach the right place.

All of them are stored the same way.

Encrypted before they're stored

Every key is encrypted with AES-256-GCM before it's written to the database. Each value gets its own random starting value, so the same key saved twice never looks the same twice. GCM adds a check on every value, so a stored key that's been tampered with fails to open instead of opening wrong.

The encryption key comes from a server secret that lives outside the database. In production, Stage 1 refuses to work without a strong one set. So a copy of the database on its own holds keys nobody can read.

The nightly backups are copies of that same database, and Stage 1 keeps the last seven. The keys in them are just as encrypted.

Never shown again

Once you save a key, Stage 1 never sends it back to your browser. The connections screen knows which keys are saved and when. It doesn't know what they are.

Open Settings, Connections after saving and the field is empty, with a note that reads Saved. Paste a new value to replace it. Tokens and API keys go into password fields, so they don't sit on screen in plain text as you type either. To remove one, click Disconnect.

Only the workspace owner can add, change or remove connections. A teammate can use what's connected. They can't see it or change it.

Your password never reaches us

For LinkedIn and email, most firms don't paste a key at all. Click Connect, sign in on a secure page run by Unipile, and Stage 1 gets a connection to the account without ever seeing your password. More on that in Stage 1 runs on your own LinkedIn and email.

The rest of the lock

Connection keys are one part of it. Passwords are hashed with scrypt. Sessions are stored only as hashes, so a leaked database can't be replayed as logins. Every account, contact and message belongs to one workspace, and nothing is shared between customers. Slack button clicks are checked against Slack's signature before Stage 1 acts on them. The full list is on the security page.

Why this matters for a services firm

A services firm sells trust. A partner's LinkedIn holds decades of relationships, and the firm's inbox holds every client conversation. If either is used to send something the partner didn't write, the damage lands on the firm's name, with buyers who remember.

That makes a security review part of buying a sales tool, and it should be. Your IT lead will ask where the keys live, who can read them and what happens if the database leaks. Stage 1 has a short answer to each one. Encrypted, nobody in the app, and nothing usable.

For why trust is the whole game in a services sale, read trust is the product, and for why every send still has a person behind it, owning every send.

Paste a key once. After that, nobody sees it, including you.

See which of your accounts are moving.

Stage 1 reads your site, finds accounts that fit and checks their filings and news. Your first Board in about two minutes. Free for 14 days, no credit card.