Security

Senitix CRM security: data protection, access control and audit

Senitix CRM data is hosted in the EU and encrypted in transit and at rest, access is set by role and field, and field history and an audit trail record who changed what. Senitix holds no SOC 2 report or ISO 27001 certificate today; a SOC 2 Type II audit is in preparation.

Controls

How does Senitix protect customer data?

Six controls and what each one covers. Plan details are on the pricing page.

Encryption in transit and at rest

Connections use TLS 1.2 at minimum and TLS 1.3 where the browser supports it, and senitix.com is on the HSTS preload list, so browsers reach it and its subdomains over HTTPS only. Databases, files and backups are encrypted at rest, and designated sensitive fields, such as a contact’s name, email and phone number, are encrypted again with AES-256-GCM under a key per workspace.

Sign-in and single sign-on

Every user can protect sign-in with an authenticator app or an SMS code, with backup codes for a lost phone, and a new password that appears in known breach data is refused. Single sign-on runs over OpenID Connect with Microsoft, Google or another OIDC provider, set up with the Senitix team. SAML is not offered today.

Roles and field-level security

Access follows role, department and record ownership, and field permissions keep a value such as margin visible only to the roles that need it. A record can also be shared by hand or restricted, and an access explorer shows why a person can see it. Each workspace is kept apart from every other at the application layer.

Audit log and field history

Field history keeps a record’s earlier values as it changes, and a setup audit trail records who changed a workspace setting and when. Both kinds of history are kept for about seven years. A deleted record goes to a recycle bin first and can be restored within 90 days by default.

Hosting in the EU

Customer data is hosted in the EU, with disaster-recovery copies in a second EU region, and there is no U.S. hosting region today. Some subprocessors, such as the email delivery service, work outside the EU; the subprocessor list names each one and where it processes data.

Backups and recovery

Databases are backed up every day and every month into a locked vault, with a copy in a second region. Daily backups are kept for 35 days and monthly backups for 365 days, and point-in-time recovery covers the last seven days. These describe how the service runs today, not a contractual recovery-time commitment.

FAQ

Security questions we get asked

Where is Senitix CRM data stored?

In the EU, with disaster-recovery copies in a second EU region, and the models behind Senitix AI also run within the EU. There is no U.S. hosting region today. A few subprocessors, such as the email delivery service, operate outside the EU; the subprocessor list names each one and where it processes data, and the Data Processing Agreement sets out the transfer terms.

Is Senitix SOC 2 or ISO 27001 certified?

Not today. Senitix holds no SOC 2 report and no ISO/IEC 27001 certificate, and a SOC 2 Type II audit is in preparation. The data centers belong to our hosting provider, whose certifications cover its own infrastructure, not the Senitix application. Until a report exists, send us your security questionnaire and we will answer it in writing; our CRM security checklist covers what a vendor security review usually asks for, beyond a certification.

Can we bring our own encryption keys?

Not yet. Customer-managed keys (BYOK), custom field-encryption rules, field masking and data loss prevention (DLP) rules are coming soon and are not available on any plan today. Every workspace already has TLS 1.2 or higher in transit, encryption at rest for databases, files and backups, and AES-256-GCM encryption of designated sensitive fields under a key Senitix manages for that workspace.

Does Senitix support SAML single sign-on?

No. Single sign-on runs over OpenID Connect instead: you can sign in through Microsoft, Google or another OIDC identity provider, and the Senitix team sets up the connection with you. SCIM user provisioning is not offered today either. Every user can add multi-factor authentication with an authenticator app or an SMS code.

Which plans include the audit log?

Field history is on every plan, Free included: it keeps a record’s earlier values as fields change. From Growth up, a setup audit trail adds who changed a workspace setting and when, and retention is about seven years on every plan that has it. Roles, departments, record ownership and field-level permissions are on every plan. The plan comparison on the pricing page shows the security and administration controls plan by plan.

How do we report a security vulnerability?

Email security@senitix.com with a description, the affected page or feature, and the steps to reproduce it. Test only against a workspace you own, do not access or change anyone else’s data, and give us reasonable time to fix the issue before you disclose it. Use the same address to report a suspected compromise of your own account.

What happens to our data if we cancel?

You can export your records as CSV or Excel files at any time, on every plan. Canceling stops renewal; you keep access through the end of the period you already paid for. Retention and deletion after that follow the Data Retention Policy, and copies already in backups age out on the backup schedule, at most 365 days later.

Ready to grow with Senitix?

Connect with customers, win more deals and grow repeat business, all on one platform.

No credit card required.