Security
Senitix CRM security: data protection, access control and audit
Senitix CRM data is hosted in the EU and encrypted in transit and at rest, access is set by role and field, and field history and an audit trail record who changed what. Senitix holds no SOC 2 report or ISO 27001 certificate today; a SOC 2 Type II audit is in preparation.
Controls
How does Senitix protect customer data?
Six controls and what each one covers. Plan details are on the pricing page.
Encryption in transit and at rest
Connections use TLS 1.2 at minimum and TLS 1.3 where the browser supports it, and senitix.com is on the HSTS preload list, so browsers reach it and its subdomains over HTTPS only. Databases, files and backups are encrypted at rest, and designated sensitive fields, such as a contact’s name, email and phone number, are encrypted again with AES-256-GCM under a key per workspace.
Sign-in and single sign-on
Every user can protect sign-in with an authenticator app or an SMS code, with backup codes for a lost phone, and a new password that appears in known breach data is refused. Single sign-on runs over OpenID Connect with Microsoft, Google or another OIDC provider, set up with the Senitix team. SAML is not offered today.
Roles and field-level security
Access follows role, department and record ownership, and field permissions keep a value such as margin visible only to the roles that need it. A record can also be shared by hand or restricted, and an access explorer shows why a person can see it. Each workspace is kept apart from every other at the application layer.
Audit log and field history
Field history keeps a record’s earlier values as it changes, and a setup audit trail records who changed a workspace setting and when. Both kinds of history are kept for about seven years. A deleted record goes to a recycle bin first and can be restored within 90 days by default.
Hosting in the EU
Customer data is hosted in the EU, with disaster-recovery copies in a second EU region, and there is no U.S. hosting region today. Some subprocessors, such as the email delivery service, work outside the EU; the subprocessor list names each one and where it processes data.
Backups and recovery
Databases are backed up every day and every month into a locked vault, with a copy in a second region. Daily backups are kept for 35 days and monthly backups for 365 days, and point-in-time recovery covers the last seven days. These describe how the service runs today, not a contractual recovery-time commitment.
Security review
Documents for your security and legal review
The contract documents are published and linked below. Questionnaires go through the contact form, and vulnerability reports go to the security address.
Data Processing Agreement
Roles, processing instructions, security measures, breach notice and transfer terms for the customer data you put in Senitix.
Read the DPASubprocessors
Each third party that processes personal data for Senitix, the service it provides and where it processes the data.
See the listPrivacy Policy
What Senitix collects for accounts, billing and this website, why it collects it, and the privacy rights you can use.
Read the policyData Retention Policy
How long each kind of data is kept, backups included, and how it is deleted when that period ends.
Read the policySecurity questionnaire
Send your security or vendor-risk questionnaire. The contact form opens with the Security, privacy & legal topic already selected.
Send a questionnaireReport a vulnerability
Email the steps to reproduce. Test only against your own workspace, and never access or change another customer’s data.
security@senitix.comFAQ
Security questions we get asked
Where is Senitix CRM data stored?
In the EU, with disaster-recovery copies in a second EU region, and the models behind Senitix AI also run within the EU. There is no U.S. hosting region today. A few subprocessors, such as the email delivery service, operate outside the EU; the subprocessor list names each one and where it processes data, and the Data Processing Agreement sets out the transfer terms.
Is Senitix SOC 2 or ISO 27001 certified?
Not today. Senitix holds no SOC 2 report and no ISO/IEC 27001 certificate, and a SOC 2 Type II audit is in preparation. The data centers belong to our hosting provider, whose certifications cover its own infrastructure, not the Senitix application. Until a report exists, send us your security questionnaire and we will answer it in writing; our CRM security checklist covers what a vendor security review usually asks for, beyond a certification.
Can we bring our own encryption keys?
Not yet. Customer-managed keys (BYOK), custom field-encryption rules, field masking and data loss prevention (DLP) rules are coming soon and are not available on any plan today. Every workspace already has TLS 1.2 or higher in transit, encryption at rest for databases, files and backups, and AES-256-GCM encryption of designated sensitive fields under a key Senitix manages for that workspace.
Does Senitix support SAML single sign-on?
No. Single sign-on runs over OpenID Connect instead: you can sign in through Microsoft, Google or another OIDC identity provider, and the Senitix team sets up the connection with you. SCIM user provisioning is not offered today either. Every user can add multi-factor authentication with an authenticator app or an SMS code.
Which plans include the audit log?
Field history is on every plan, Free included: it keeps a record’s earlier values as fields change. From Growth up, a setup audit trail adds who changed a workspace setting and when, and retention is about seven years on every plan that has it. Roles, departments, record ownership and field-level permissions are on every plan. The plan comparison on the pricing page shows the security and administration controls plan by plan.
How do we report a security vulnerability?
Email security@senitix.com with a description, the affected page or feature, and the steps to reproduce it. Test only against a workspace you own, do not access or change anyone else’s data, and give us reasonable time to fix the issue before you disclose it. Use the same address to report a suspected compromise of your own account.
What happens to our data if we cancel?
You can export your records as CSV or Excel files at any time, on every plan. Canceling stops renewal; you keep access through the end of the period you already paid for. Retention and deletion after that follow the Data Retention Policy, and copies already in backups age out on the backup schedule, at most 365 days later.
