Skip to content

Security & privacy

Your Data, Under Your Control and Protected

Your customer data is your business. Here is, in plain language, how CRModular protects it.

Tenant isolation

  • Every record belongs to a company; every query is scoped to the company ID.
  • Users of one company cannot see or change another company's data.

Permissions

  • Object-level read/create/edit/delete permissions via profiles and permission sets.
  • Record-level access through the role hierarchy and sharing rules: users can be limited to their own or their team's records.
  • Administration screens are restricted to the admin role.

Sign-in and session security

  • Passwords are stored one-way hashed (bcrypt); no plain-text passwords.
  • Per-company password policy; accounts are temporarily locked after repeated failed sign-ins.
  • Password reset links are single-use; invited users must change their password on first sign-in.
  • Rate limiting and brute-force protection.

Data protection

  • Connection passwords such as SMTP/IMAP are stored encrypted with AES-256-GCM.
  • Record changes are written to a history log: who changed what and when.
  • Deletes are reversible by default (deactivation).

Privacy (KVKK/GDPR-style) tools

  • Consent records per contact and lead (source, date, IP).
  • Contacts who revoke consent are excluded from mass email and cadences; every email has an unsubscribe link.
  • Deletion/anonymization request workflow and data inventory.

Roadmap

Two-factor authentication (2FA) is not available yet; it is on our roadmap. We will announce it on this page when it ships.

Write to us to report a vulnerability or for security questions before signing a contract.

Contact

Bring your sales and service teams onto one platform

Try every module free for 14 days, no credit card required. Our team helps you get set up.