Security and delivery

The operating boundary is part of the system design.

Security questions are answered during scope, before production data or users are introduced. The exact controls depend on the deployment model agreed with the client.

Review areas

Six decisions we document before production use.

01

Deployment boundary

Hosting region, customer-owned or managed infrastructure, network access and data location are agreed in the written scope.

02

Data ownership

Client data remains the client’s data. Export, handover and deletion responsibilities are defined before production use.

03

Access control

The CRM supports tenant separation, role permissions and record-level access. Administrative access is limited to agreed support responsibilities.

04

Authentication

Email/password access can be controlled per workspace. Microsoft Entra ID integration is supported when configured, and password login can be disabled for SSO-only tenants.

05

Backups and recovery

Backup frequency, retention, restore testing and recovery responsibilities are agreed for the selected hosting model. No recovery target is implied until it is written into scope.

06

Changes and support

Releases are reviewed against acceptance records. Support routes, severity handling and maintenance windows are agreed for each engagement.

Public CRM boundary

The online workspace is a disposable demonstration.

It contains fictional organisations and illustrative figures only. Visitors should not enter personal data, confidential records or production credentials. Demo records may be reset without notice.

Customer environments are deployed separately and do not share the public sample database.

Make an enquiry

Request a security and deployment review for your workflow.

Share one example. We reply within one business day with the next useful question.

Make an enquiry