The relationship CRM for consulting firms.Log in / Start free
Easy CRM 360 Start free

Security

How we protect your firm's data.

Easy CRM 360 holds your firm's relationships, so we protect them the way the big CRMs do, without charging enterprise prices for it. Every item below is included on every plan.

Encryption

  • In transit: every connection uses HTTPS (TLS 1.2 or 1.3). Browsers are told to never connect without it (HSTS).
  • At rest: the database and backups are encrypted with AES-256 by our hosting provider, Cloudflare.
  • A second layer for sensitive text: notes on timelines, logged and forwarded emails, and attachments are encrypted again by Easy CRM 360 itself (AES-256-GCM) before they are stored. The key is kept apart from the database, so a copy of the database alone cannot be read.

Signing in

  • Passwords are never stored, only salted PBKDF2 hashes of them.
  • Two-step sign-in with any authenticator app (Microsoft Authenticator, Google Authenticator and others), with one-time recovery codes. Owners can require it for everyone in the firm.
  • Five wrong passwords in a row lock password sign-in for 15 minutes.
  • Firms can sign people out automatically after a period of inactivity.
  • Emailed sign-in links work once and expire after 15 minutes. Google sign-in is also available.
  • Sign-in cookies are secure, HTTP-only and cannot be read by page scripts.

Who can see what

  • Each firm's data is kept separate. Every request is checked against the signed-in person's firm.
  • Owners and admins control who is on the team and what role they have.
  • Activity log: sign-ins, failed sign-ins, exports, imports, deletions, bulk changes, team changes and security changes are recorded with time, person and IP address. Owners and admins can review it and download it.
  • Our own staff do not look at your firm's records unless you ask us to, for support.

Where it runs

  • Cloudflare hosts the application and database (Cloudflare holds SOC 2 Type II and ISO 27001 certifications).
  • Stripe handles payments (PCI DSS Level 1). Card numbers never reach our systems.
  • Resend delivers email. Google is used only if you choose Google sign-in.
  • We do not sell your data or use it for advertising.

Your data

  • Your firm owns its data. Export contacts and companies to a spreadsheet at any time.
  • Ask us to delete your firm's data and we will within 30 days; backups age out within 90 days.
  • Keep sensitive personal data out of notes: no passwords, card or bank numbers, Social Security numbers or health details. The app reminds everyone of this next to every notes box.

If something goes wrong

  • If a security incident affects your firm's data, we will tell your firm's owner without undue delay, and within 72 hours of confirming it, with what happened and what we are doing about it.
  • To report a security problem, email hello@edgewater-media.com. We respond to every report.

Security questionnaires

Working with a client that sends vendor security questionnaires? Email hello@edgewater-media.com and we will help you answer them.