Who sees what, who changed it, and where it lives
A CRM holds the most sensitive thing you own — your customers. We build to that: role-based access down to the field, an audit trail of every change, encryption at rest and in transit, and data that stays in a region you choose, on infrastructure you can own.
Field-level access · Full audit log · Encrypted · Data residency you choose
Each role sees only its part of the file
Not a single “admin or not” switch. Access is defined per role and per field, so reception, sales and finance each work with what they need and nothing they don't.
Every change, with a name against it
Who changed the price, who exported the list, who deleted the record — recorded permanently, next to the record itself. Not to catch people out, but so a question always has an answer.
priya.nair changed Deal value
₹4.0L → ₹4.2L on lead #5219
rahul.m exported Leads
142 rows · with filters
admin granted role
Finance access to s.rao
neha.g deleted note
on contact #1042 — recoverable
s.rao signed in
new device · Pune
Kept next to the record and exportable — there to answer a question, not to catch anyone out.
Where the data lives, and how it's kept
The parts your security review will ask about — answered the way an in-house team would want, and open to your own audit before we start.
Encrypted end to end
AES-256 at rest, TLS 1.3 in transit. Backups and file storage encrypted too.
Tested backups
Daily automated backups, actually restored into a scratch environment each month.
Data residency
Hosted in an Indian region by default, or a region your policy requires.
On your own servers
Where regulation demands it, the whole system runs on infrastructure you control.
For regulated sectors — lending, healthcare, foreign-funded non-profits — we design to your specific obligations during discovery rather than to a generic default. We are not your legal advisor, but the system is built so the data you need to comply is captured cleanly, not reconstructed later.
Send us your security review checklist
We would rather answer it before you ask than after an incident. Bring your requirements — access, residency, audit, retention — and we will show how the build meets them.
- Role and field-level access you define
- An immutable audit trail of every change
- Encrypted at rest and in transit, backups tested
- Data residency you choose — or your own servers