Built for the agencies and the auditors. Secure by architecture.
Tenant isolation, field-level encryption, append-only audit log, state-law retention defaults. Compliance-grade from Day 1.
Eleven controls, one architecture.
Every layer is built in, not bolted on — from tenant isolation at the database to append-only audit trails and state-law retention defaults.
Tenant isolation
Every CRM table enforces Supabase Row-Level Security (RLS). Every query carries an org_id derived from the JWT — set server-side, never trustable from a request body. Cross-tenant data access is structurally impossible.
Field-level encryption for PII
Email, phone, and other personally identifiable fields are encrypted at rest with per-org keys. Blind indexing lets you search encrypted columns without decrypting them. Even a database leak doesn't expose plaintext PII.
Append-only audit log
Every CRM write, login, role change, settings change, webhook delivery, API call, and export is captured. Searchable by actor, resource, action, date range. Exportable to CSV. Tamper-evident at Scale tier.
Retention policies (state-law defaults)
Out-of-the-box retention rules per object type, set to defaults that meet US state insurance regulations:
- Policies — 10 years (DOI requirement)
- Clients — 7 years (state privacy + E&O)
- Service Requests — 5 years
- Opportunities & Quotes — 5 years
- Tasks — 3 years
Configurable per agency. Override per object type if your state requires longer.
Legal hold with typed reasons
Place individual records on legal hold with typed reasons: Active Litigation, DOI Audit, Regulatory Investigation, or Other. Holds suspend retention purges until released. Optional expiration date.
Retention simulation
Preview exactly what will be purged before it runs. Inspect every record on the chopping block. Cancel or hold any individual record. Audit history of every purge.
GDPR + CCPA support
Client portal includes data export and deletion request flows out of the box. Requests tracked with status timeline. Right-to-be-forgotten via admin script. IP addresses hashed (not stored raw) on the waitlist signup.
Role-based access control
7 roles (Owner, Admin, Team Lead, Producer, CSR, Account Manager, Viewer) with hierarchical permissions. 31-key entitlement registry. Per-user override matrix lets admins toggle individual feature access with tri-state Allow/Deny/Inherit.
SOC2 + on-prem AI
Scale tierSOC2 documentation package available at Scale tier. Full Type II audit completing 2026. On-prem AI option at Enterprise tier — bring your own Ollama / vLLM endpoint via our OpenAI-compatible provider layer.
Infrastructure
Supabase (PostgreSQL + Auth + Storage + Realtime), Google Cloud Run (backend), Vercel (frontend), Sentry (error tracking). Multi-region deployment available at Enterprise tier.
No third-party data sharing
We don't sell, share, or analyze your agency's CRM data. AI tools (Anthropic, OpenAI, Synthflow) operate on a per-request basis — providers don't train on your data. Self-hosted AI option available at Enterprise tier if you need full air-gap.
Built for trust.
Get early access. Bring your security team.