Draft. Underlined items marked CONFIRM need your sign-off before launch. Remove data-draft from the page wrapper to hide these markers.

Security

How CRMSix protects your customer data

What we do today, what we are working towards, and how to report a problem. If your security team needs more detail, ask us and we will answer in writing.

Tenant isolation
Row-level security on every query
Sign-in
SSO over OpenID Connect
Access control
Agent, manager and admin profiles
Accountability
Setup audit trail and login history
Integrations
Read-only scopes, revocable keys
Transport
HTTPS only

Data isolation

CRMSix is a multi-tenant service. Every record belongs to one organization, and row-level security enforces that boundary in the database itself, on every read and write. A request made for one organization cannot return another organization's rows, even if application code has a bug.

Identity and access

  • Sign in through your identity provider over OpenID Connect, including Okta, Microsoft Entra ID and Google. Single sign-on is included in every paid plan.
  • Enforce multi-factor authentication, session length and offboarding in your identity provider. When you disable someone there, they can no longer sign in to CRMSix.
  • Give each person an agent, manager or admin profile. Team-based sharing decides which cases, accounts and deals they can see.

Audit trail

Every change in Setup is recorded with who made it, when, and what changed. Each user's login history is kept alongside it, so an admin can answer "who changed this rule?" or "when did this person last sign in?" without contacting us.

Retention: the Setup audit trail is kept for 180 days, login history for 6 months, and field history for 18 months.

Integrations and AI assistants

  • API keys and OAuth apps can be limited to read-only access and revoked at any time.
  • AI assistants connect over the Model Context Protocol and sign in as the user through OAuth. They see and change only what that user is allowed to, and an admin can make AI access read-only with one switch.
  • CRMSix does not use your data to train AI models.

Encryption

  • CRMSix is served over HTTPS only. Connections use TLS 1.2 or later, with HSTS enabled.
  • Secrets such as SSO client credentials are encrypted at rest by the application.
  • All customer data is encrypted at rest by our database provider using AES-256.

Hosting and backups

Application hostingProvider name
DatabaseProvider name
Primary data regionRegion, for example Mumbai (ap-south-1)
BackupsDaily, kept for 7 days, with point-in-time recovery
Service statusstatus.crmsix.com

Compliance

We list only what is true today. Items marked planned are on our roadmap and are not yet in place.

Standard or lawStatusDetail
India DPDP Act, 2023In placeCRMSix acts as a data processor for your organization
EU GDPRIn placeData processing agreement available on request
Independent penetration testPlannedFirst test scheduled for Q1 2027; summary shared under NDA
SOC 2 Type IIPlannedNot started
ISO/IEC 27001PlannedNot started

Subprocessors

These companies process customer data on our behalf. We will update this list before adding a new one.

CompanyPurposeLocation
CompanyApplication hostingRegion
CompanyDatabase and file storageRegion
CompanyEmail deliveryRegion

Report a vulnerability

If you find a security issue, email us before disclosing it publicly. Include the steps to reproduce it and the account or URL involved.

security@crmsix.com
  • We reply within two business days and keep you updated until the issue is fixed.
  • We will not take legal action against research done in good faith that avoids privacy violations, data destruction and service disruption.
  • Our contact details are also published at /.well-known/security.txt.

See CRMSix with your own cases and deals

A 30-minute walkthrough, set up around how your team works today.