New — crm.care can now be fully managed: we brief, build and ship your campaigns for you. See the Managed plan →
SECURITY · INCLUDING THE GAPS

Security.

Last updated 18 August 2026

In place

What is
in place.

Nothing here is aspirational. If it says in place, it is in place today.

01

Platform access by OAuth only

We never ask for or store Salesforce, AE or HubSpot credentials. Tokens are encrypted at rest and revocable from your side at any time.

02

Least-privilege scopes

We request the scopes needed to read attribution and publish the artefacts you approve. No administrative scopes.

03

Encryption and hosting

UK-hosted. TLS 1.3 in transit, AES-256 at rest, encrypted backups with 30-day retention.

04

Action logging

Every agent action against your platform is logged with user, time and payload, and is undoable. See Autonomy.

05

Roles and approvals

Per-workspace roles, approval flow on Team and above, SSO (Okta, Azure AD) on Growth.

06

No training on your data

Commercial model endpoints with training disabled. Your prospect database never leaves for a model provider.

Not yet

What we do
not have yet.

We would rather you read it here than find it in a procurement questionnaire.

SOC 2

In progress

Type I in preparation. No report to share yet; we will not claim otherwise until there is one.

ISO 27001

Not started

On the roadmap after SOC 2, not before.

Pen test

Annual, next Q4

The executive summary is shared under NDA once it exists.

Bug bounty

Email disclosure

No formal programme yet. Email security@crm.care and we respond within 72 hours.

Questions about this document? Email legal@crm.care and a human replies.