Security & reliability

How your data is handled

A CRM holds the record of every relationship a business has. This page describes the controls around that, in ordinary language, including the parts that depend on you rather than on us.

Encryption

Traffic is encrypted in transit using current TLS. Stored data and backups are encrypted at rest. Keys are managed separately from the systems that use them.

Access control

Role-based permissions on every record type, with field-level controls available on the Scale plan. Administrative access is limited and logged.

Authentication

Multi-factor authentication is available on all plans and can be enforced for an entire account. Single sign-on is available on the Scale plan.

Backups

Automated backups run on a fixed schedule and are tested by periodic restore, because an untested backup is only a hypothesis.

Isolation

Customer data is logically separated, and no data is shared, pooled or resold between accounts under any circumstances.

Audit trail

Record changes are attributed to a user with a timestamp. On the Scale plan the full audit trail is exportable.

Availability

The service runs across multiple availability zones with automated failover. Planned maintenance is announced in advance and scheduled outside common business hours where that is possible across regions.

When something does go wrong, we would rather post an unflattering incident note than a vague one. Nobody has ever been reassured by "elevated error rates" as a complete explanation.

Your side of it

A meaningful share of CRM data incidents involve credentials rather than infrastructure. The controls that help most are ones only you can apply:

  • Enforce multi-factor authentication account-wide
  • Remove access promptly when people leave
  • Review who holds administrative rights, periodically
  • Scope API tokens narrowly and rotate them
  • Limit bulk export rights to people who need them

Data location and retention

Data is stored in the region selected when an account is created. While an account is active, records are kept until you delete them. After an account closes, data is retained for a limited recovery window and then removed from live systems, with backups ageing out on their own schedule.

Sub-processors

Running the service involves a small number of infrastructure providers. The current list is available on request, and material changes are notified to account administrators before they take effect.

Reporting a vulnerability

If you believe you have found a security issue, email [email protected] with enough detail to reproduce it. We will acknowledge the report, keep you updated while it is investigated, and will not pursue action against good-faith research that avoids privacy violations and service disruption.

What this page deliberately does not do is display certification badges. Compliance logos are easy to put on a website and tell you very little on their own. If your procurement process needs specific documentation, ask us directly and we will tell you plainly what we can and cannot provide.

Security review as part of your evaluation?

Send the questionnaire over. We would rather answer it early than discover a blocker at the end.

Get in touch