Skip to content
Security & Compliance

Who sees what, who changed it, and where it lives

A CRM holds the most sensitive thing you own — your customers. We build to that: role-based access down to the field, an audit trail of every change, encryption at rest and in transit, and data that stays in a region you choose, on infrastructure you can own.

Field-level access · Full audit log · Encrypted · Data residency you choose

Role-based access

Each role sees only its part of the file

Not a single “admin or not” switch. Access is defined per role and per field, so reception, sales and finance each work with what they need and nothing they don't.

CapabilityReceptionSalesFinanceAdmin
Customer contact details
Deal value & pricing
Payment & bank details
Discount approval
Export to Excel
User & role management
FullView onlyNo accessYou define this matrix
The audit trail

Every change, with a name against it

Who changed the price, who exported the list, who deleted the record — recorded permanently, next to the record itself. Not to catch people out, but so a question always has an answer.

Audit log · todayimmutable

priya.nair changed Deal value

₹4.0L → ₹4.2L on lead #5219

rahul.m exported Leads

142 rows · with filters

admin granted role

Finance access to s.rao

neha.g deleted note

on contact #1042 — recoverable

s.rao signed in

new device · Pune

Kept next to the record and exportable — there to answer a question, not to catch anyone out.

Data protection

Where the data lives, and how it's kept

The parts your security review will ask about — answered the way an in-house team would want, and open to your own audit before we start.

Encrypted end to end

AES-256 at rest, TLS 1.3 in transit. Backups and file storage encrypted too.

Tested backups

Daily automated backups, actually restored into a scratch environment each month.

Data residency

Hosted in an Indian region by default, or a region your policy requires.

On your own servers

Where regulation demands it, the whole system runs on infrastructure you control.

For regulated sectors — lending, healthcare, foreign-funded non-profits — we design to your specific obligations during discovery rather than to a generic default. We are not your legal advisor, but the system is built so the data you need to comply is captured cleanly, not reconstructed later.

On security

What security reviews ask

Something specific to your setup? Ask an engineer

Send us your security review checklist

We would rather answer it before you ask than after an incident. Bring your requirements — access, residency, audit, retention — and we will show how the build meets them.

  • Role and field-level access you define
  • An immutable audit trail of every change
  • Encrypted at rest and in transit, backups tested
  • Data residency you choose — or your own servers