Draft. Underlined items marked CONFIRM need your sign-off before launch. Remove data-draft from the page wrapper to hide these markers.
Security
How CRMSix protects your customer data
What we do today, what we are working towards, and how to report a problem. If your security team needs more detail, ask us and we will answer in writing.
Tenant isolation
Row-level security on every query
Sign-in
SSO over OpenID Connect
Access control
Agent, manager and admin profiles
Accountability
Setup audit trail and login history
Integrations
Read-only scopes, revocable keys
Transport
HTTPS only
Data isolation
CRMSix is a multi-tenant service. Every record belongs to one organization, and row-level security enforces that boundary in the database itself, on every read and write. A request made for one organization cannot return another organization's rows, even if application code has a bug.
Identity and access
Sign in through your identity provider over OpenID Connect, including Okta, Microsoft Entra ID and Google. Single sign-on is included in every paid plan.
Enforce multi-factor authentication, session length and offboarding in your identity provider. When you disable someone there, they can no longer sign in to CRMSix.
Give each person an agent, manager or admin profile. Team-based sharing decides which cases, accounts and deals they can see.
Audit trail
Every change in Setup is recorded with who made it, when, and what changed. Each user's login history is kept alongside it, so an admin can answer "who changed this rule?" or "when did this person last sign in?" without contacting us.
Retention: the Setup audit trail is kept for 180 days, login history for 6 months, and field history for 18 months.
Integrations and AI assistants
API keys and OAuth apps can be limited to read-only access and revoked at any time.
AI assistants connect over the Model Context Protocol and sign in as the user through OAuth. They see and change only what that user is allowed to, and an admin can make AI access read-only with one switch.
CRMSix does not use your data to train AI models.
Encryption
CRMSix is served over HTTPS only. Connections use TLS 1.2 or later, with HSTS enabled.
Secrets such as SSO client credentials are encrypted at rest by the application.
All customer data is encrypted at rest by our database provider using AES-256.
Hosting and backups
Application hosting
Provider name
Database
Provider name
Primary data region
Region, for example Mumbai (ap-south-1)
Backups
Daily, kept for 7 days, with point-in-time recovery
Service status
status.crmsix.com
Compliance
We list only what is true today. Items marked planned are on our roadmap and are not yet in place.
Standard or law
Status
Detail
India DPDP Act, 2023
In place
CRMSix acts as a data processor for your organization
EU GDPR
In place
Data processing agreement available on request
Independent penetration test
Planned
First test scheduled for Q1 2027; summary shared under NDA
SOC 2 Type II
Planned
Not started
ISO/IEC 27001
Planned
Not started
Subprocessors
These companies process customer data on our behalf. We will update this list before adding a new one.
Company
Purpose
Location
Company
Application hosting
Region
Company
Database and file storage
Region
Company
Email delivery
Region
Report a vulnerability
If you find a security issue, email us before disclosing it publicly. Include the steps to reproduce it and the account or URL involved.
security@crmsix.com
We reply within two business days and keep you updated until the issue is fixed.
We will not take legal action against research done in good faith that avoids privacy violations, data destruction and service disruption.
Our contact details are also published at /.well-known/security.txt.
See CRMSix with your own cases and deals
A 30-minute walkthrough, set up around how your team works today.