Security at CRM For AI
The short version: your records sit in a database that holds only your account's data, CRM For AI never touches your email, and you can export or delete everything whenever you want. The details follow.
Your data is isolated
- One database per account. Each account's contacts, companies, deals, notes and settings live in their own database. There is no shared table holding several customers' records, and no tool or page can query two accounts at once.
- The account comes from your sign-in, never from a request. Which database a request reaches is decided by the signed token your assistant holds. No tool accepts an account id as input, so neither a mistaken nor a manipulated request can point at someone else's data.
- Tested on every change. An automated test creates two accounts and tries every tool and account-page action from one with the other's ids; every attempt must fail.
CRM For AI never touches your email
CRM For AI holds no mailbox access and no email credentials, and it never sends email, texts or any message to your contacts. When you ask your assistant to work your inbox, your assistant reads your mail with your own email connection and records in CRM For AI only what you ask it to. The only emails CRM For AI sends go to you and your team about your own account: sign-in codes, invitations, export links and plan notices.
Email examples require connecting your email account (for example Gmail or Outlook) to your AI assistant. CRM For AI never reads or sends email itself; your assistant reads your mail and records what you ask it to in CRM For AI.
Sign-in and connections
- Assistants connect with OAuth 2.1 and PKCE, the standard for connecting apps. You sign in with a one-time code sent to your email; CRM For AI has no passwords to steal.
- On the consent screen you choose full access or read-only for each assistant. Each connection can be ended at any time from your account page.
- In a shared workspace, each person signs in as themselves and acts within their role (admin, member or viewer). Removing someone ends their access through every connection at once.
- Requests are rate-limited per account.
Encryption
- Everything travels over HTTPS (TLS).
- Databases and stored files are encrypted at rest by our hosting provider, Cloudflare.
- Download links for exports and upload links for imports are signed, tied to your account, and expire (exports after 24 hours, upload links after 30 minutes).
Protecting you from what your assistant reads
An assistant can be misled by text it reads, including notes and emails. CRM For AI treats every stored text as data, never as instructions: it is marked as such when returned to the assistant, deleting records always needs an explicit confirmation, closing deals and removing pipeline stages ask first, and deletions go to a 30-day trash. The screens shown inside the chat run in the assistant's sandbox, display record text as plain text, and can only call CRM For AI's own tools with your existing connection.
Reversible by default
- Deleted contacts, companies, deals and notes stay in a trash for 30 days and can be restored.
- Imports can be undone for seven days.
- Every change is recorded in an activity log you can read from the chat (kept for a year).
- Our hosting provider keeps point-in-time recovery of each database for 30 days. We keep no other backups.
Export and deletion
Export contacts, companies, deals, notes and templates as CSV or JSON on every plan. Exporting every record of a kind asks you to confirm outside the assistant (in its own question, or on your account page when it cannot ask), and the download link goes to you by email instead of into the chat. The account owner is emailed whenever an export produces a download file; small exports returned straight into the chat and new assistant connections are not emailed (connected assistants are listed on the account page). The account owner can request a full export from the account page. Deleting your account from the account page removes everything 30 days after you ask (you can cancel until then): the database, files, connections, sessions, members' access to the workspace and usage records; point-in-time recovery copies expire within 30 days after that. Feature requests you sent keep their one-line summary, without anything that links them to you.
What we log, and what we don't
Our logs and usage analytics record which tool was used, how long it took, counts and error codes. They never contain names, email addresses, the text of your records or the values you searched for. Product usage events carry a pseudonymous account id.
What not to store
CRM For AI is built for business contact details, companies, deals and notes about your working relationships. Please don't store payment card numbers, government IDs, health information, passwords, API keys or other special-category personal data.
Our operators
Our staff use an internal console behind Cloudflare Access with individual accounts. It shows account-level facts (plan, usage counts, connections) and never your records. Every operator action is recorded.
Where your data is stored
On Cloudflare. We do not pick a location for each account's database today: Cloudflare places it, usually near where the account is first used. The account directory and stored files carry a location hint for eastern North America. Choosing European Union storage is planned for v1.1 (Growth and Scale plans).
Sub-processors
These companies process data on our behalf. We will give 30 days' notice of changes on this page and by email to account owners.
| Company | What they do for us | Location | When |
|---|---|---|---|
| Cloudflare, Inc. | Hosting and storage: the servers, each account's database, the account directory, uploaded and exported files, the usage queue, DNS and network protection; access control for our operators. | Global network. Each account's database is placed by Cloudflare, usually near where the account is first used; the account directory and files carry a location hint for eastern North America | Always |
| Stripe, Inc. | Payments, subscriptions, invoices, tax calculation and the billing portal. Receives the account owner's email, billing details and the plan; never your CRM records. | United States | When you buy a plan |
| Resend | Sends our emails to you: sign-in codes, invitations, export links and account notices. Receives your email address and the message; never your CRM records. | United States | Always |
| Google LLC (BigQuery) | Product usage analytics: counts of events such as “a contact was created” or “a report was viewed”, with a pseudonymous account id. No names, email addresses, record content or filter values. | United States | Only when usage analytics are enabled |
Your AI assistant (for example ChatGPT or Claude) is not our sub-processor: you choose it, and what it does with the conversation is covered by its own terms.
Planned, not in use yet
We will add these to the table, with notice, before they process any data: Google Workspace (Google LLC), to send our emails in place of Resend; and, for automated support, an AI provider and an email service for the support inbox [vendors to confirm]. We use no error-reporting service. Our source code is hosted on GitHub, which holds no customer data.
Not yet in place
We are a young product and say so: there is no independent audit (such as SOC 2) or external penetration test yet, and no public status page. We will list them here when they exist.
Reporting a vulnerability
Email security@crmfor.ai (also in security.txt). We acknowledge reports within two business days and follow coordinated disclosure, with a 90-day window by default. Please don't access other people's data or degrade the service while testing. For anything else, write to support@crmfor.ai.