Platform access by OAuth only
We never ask for or store Salesforce, AE or HubSpot credentials. Tokens are encrypted at rest and revocable from your side at any time.
Last updated 18 August 2026
Nothing here is aspirational. If it says in place, it is in place today.
We never ask for or store Salesforce, AE or HubSpot credentials. Tokens are encrypted at rest and revocable from your side at any time.
We request the scopes needed to read attribution and publish the artefacts you approve. No administrative scopes.
UK-hosted. TLS 1.3 in transit, AES-256 at rest, encrypted backups with 30-day retention.
Every agent action against your platform is logged with user, time and payload, and is undoable. See Autonomy.
Per-workspace roles, approval flow on Team and above, SSO (Okta, Azure AD) on Growth.
Commercial model endpoints with training disabled. Your prospect database never leaves for a model provider.
We would rather you read it here than find it in a procurement questionnaire.
Type I in preparation. No report to share yet; we will not claim otherwise until there is one.
On the roadmap after SOC 2, not before.
The executive summary is shared under NDA once it exists.
No formal programme yet. Email security@crm.care and we respond within 72 hours.
Questions about this document? Email legal@crm.care and a human replies.