Security & Data Protection
How we protect the CRM and the data within it.
1. Overview
We take reasonable measures to protect the CRM and the data within it. This page summarises our approach; it does not claim any specific external certification.
2. Authorized Access Only
Only authorized company employees can sign in. There is no public registration.
3. Role-Based Permissions
What each user can see and do is controlled by their assigned role and capabilities, enforced by the CRM.
4. Secure Authentication
Sign-in uses the platform's standard secure authentication. Users are responsible for keeping credentials confidential.
5. Encryption of Integration Tokens
Where the Google integration is used, OAuth access and refresh tokens are stored in encrypted form on the server and are never exposed to the browser, other employees, or logs.
6. Data Protection
CRM data is kept within our systems and shown only to authorized users based on role. The public website exposes no CRM, employee, customer or lead data.
7. OAuth Integrations
Google authorization uses OAuth 2.0. Employees authorize on Google's own screens (no Google password is entered into the CRM) and can disconnect at any time.
8. Employee Responsibilities
Users should protect their credentials, use only authorized access, and report any suspected security issue promptly.
9. Reporting a Concern
Security concerns can be reported to [Your Company Name] at [contact@your-company.example].