At SMBcrm, we prioritize data security, system integrity, and service continuity. Our infrastructure is built on industry best practices and leading compliance frameworks.
Last updated: January 18, 2024
Independently audited security controls
Information security management
EU data protection standards
California privacy standards
Our security program is built around four core pillars:
SMBcrm is hosted on enterprise-grade cloud infrastructure provided by Google Cloud Platform and Amazon Web Services:
We employ multiple layers of firewalls and access control lists to protect our infrastructure. All network changes follow standardized change management processes with appropriate review and approval.
Automated configuration management tools ensure consistent system baselines across our infrastructure. Our patch management program keeps all systems current with security updates.
Comprehensive logging captures security-relevant events across our infrastructure. Log access is restricted with write protection to maintain integrity. Automated threat detection monitors for suspicious activity 24/7.
Our applications are protected by multiple layers of defense:
All data transmitted to and from SMBcrm uses TLS 1.2 or higher encryption. We enforce HTTPS across all endpoints and APIs.
Customer data is encrypted at rest using AES-256 encryption. Encryption keys are managed through secure key management services with regular rotation.
Logical tenant separation ensures your data is isolated from other customers. Access controls prevent unauthorized cross-tenant data access.
SMBcrm implements robust access controls:
We comply fully with GDPR requirements for processing EU resident data. This includes:
We honor all CCPA rights for California residents, including:
We maintain a documented incident response plan that includes:
All third-party vendors undergo security review before onboarding. We require vendors to maintain appropriate security certifications and conduct regular assessments of vendor security posture.
For security questions or to report a vulnerability:
For compliance documentation requests or Data Processing Agreements, please contact your account representative or email legal@smbcrm.com.