Home / Security
Security & compliance.
A CRM holds the most sensitive asset your business owns: the record of every customer who has ever trusted you. Here is precisely how we handle it.
Encryption in transit and at rest
All traffic runs over TLS 1.2 or higher. Data at rest is encrypted using AES-256 through the storage layer of the hosting provider. Backups are encrypted with the same standard.
Least-privilege access
Role-based permissions down to the field. Staff receive the narrowest access that lets them do the job, and access is reviewed when a role changes.
Complete audit trail
Every create, update and delete is logged with the actor, the timestamp and the previous value. Audit logs are append-only and retained for the life of the system.
No card data in your CRM
We never store full card numbers, CVVs or magnetic stripe data. Card payments are handled by a PCI DSS compliant payment provider; your system holds tokens and references only.
Secrets management
API keys and credentials live in a managed secrets vault, never in source code, never in a shared document, and are rotated on staff change.
Testing before release
Automated dependency scanning on every build, peer code review on every change, and a written pre-launch security review before a system goes live.
Backups and recovery
Automated daily backups with point-in-time recovery. Restore procedures are tested, not assumed, and the runbook is handed to you.
Segregated environments
Development, staging and production are fully separated. Production data is never copied into a development environment without irreversible anonymisation.
Incident response
A written incident procedure with defined severities. Clients are notified of any incident affecting their data without undue delay and always within seventy-two hours.
Compliance posture
What we do and do not claim.
We state our position plainly. A vendor that overstates its certifications is a risk in itself.
| Area | Our position |
|---|---|
| PCI DSS | Systems we build are designed so that cardholder data never enters them. Card processing is delegated to a PCI DSS Level 1 compliant provider, which keeps your CRM out of scope. |
| GDPR & UK GDPR | We build the mechanics of compliance — consent records, data export, right-to-erasure workflows and retention rules. Where we process personal data on your behalf we act as a processor under a written data processing agreement. |
| CCPA / CPRA | Supported through the same export, deletion and disclosure tooling. We do not sell personal information, and never share client data between clients. |
| SOC 2 | We are not currently SOC 2 certified and do not claim to be. We build to the practices above and will work within your auditor's requirements where you hold a certification. |
| HIPAA | We do not currently accept engagements involving protected health information. |
| Data residency | United States regions by default. Other regions available on request where a client has a residency requirement. |
| Subcontracting | Delivery is performed by our own United States based team. We do not subcontract client data access to third parties without written client consent. |
Report a concern
Found something? Tell us.
If you believe you have found a vulnerability in a system we operate, we want to hear from you directly and we will not pursue action against good-faith research.
Write to legal@trustedventures.store with steps to reproduce. We acknowledge every report within two business days and will keep you updated until it is resolved.
- Encryption in transit
- TLS 1.2+
- Encryption at rest
- AES-256
- Backup frequency
- Daily, with point-in-time recovery
- Incident notification
- Within 72 hours
- Default data residency
- United States
- Card data stored
- None
