SECURITY

Built for the agencies and the auditors. Secure by architecture.

Tenant isolation, field-level encryption, append-only audit log, state-law retention defaults. Compliance-grade from Day 1.

CONTROLS

Eleven controls, one architecture.

Every layer is built in, not bolted on — from tenant isolation at the database to append-only audit trails and state-law retention defaults.

Tenant isolation

Every CRM table enforces database-level row security. Every query is scoped to your agency server-side — never trusted from the request. Cross-tenant data access is structurally impossible.

Field-level encryption for PII

Email, phone, and other personally identifiable fields are encrypted at rest with per-agency keys — and stay searchable without ever exposing plaintext. Even a database leak doesn't expose PII.

Append-only audit log

Every CRM write, login, role change, settings change, webhook delivery, API call, and export is captured. Searchable by actor, resource, action, date range. Exportable to CSV. Tamper-evident by design.

Retention policies (state-law defaults)

Out-of-the-box retention rules per object type, set to defaults that meet US state insurance regulations:

  • Policies — 10 years (DOI requirement)
  • Clients — 7 years (state privacy + E&O)
  • Service Requests — 5 years
  • Opportunities & Quotes — 5 years
  • Tasks — 3 years

Configurable per agency. Override per object type if your state requires longer.

Legal hold with typed reasons

Place individual records on legal hold with typed reasons: Active Litigation, DOI Audit, Regulatory Investigation, or Other. Holds suspend retention purges until released. Optional expiration date.

Retention simulation

Preview exactly what will be purged before it runs. Inspect every record on the chopping block. Cancel or hold any individual record. Audit history of every purge.

GDPR + CCPA support

Client portal includes data export and deletion request flows out of the box. Requests tracked with a status timeline. Right-to-be-forgotten built in.

Role-based access control

7 roles (Owner, Admin, Team Lead, Producer, CSR, Account Manager, Viewer) with hierarchical permissions, plus per-user overrides when someone needs an exception — admins control exactly who sees what.

Tamper-evident audit trail

Every tier

The audit log is hash-chained — every entry sealed against silent edits, on every tier, never sold back to you as an upgrade. For a full air-gap, an on-prem AI option is available at the Enterprise tier.

Infrastructure

Enterprise-grade managed cloud: encrypted in transit and at rest, continuously monitored, automatically backed up, and deployed with regional redundancy.

No third-party data sharing

We don't sell, share, or analyze your agency's CRM data. Our AI providers operate on a per-request basis and never train on your data. A self-hosted AI option is available at the Enterprise tier if you need full air-gap.

Built for trust.

Get early access. Bring your security team.

By joining, you agree to receive launch updates. Unsubscribe anytime.