Who sees what,down to the row.
A CRM holds the phone number of every client you have. This is the account of how that data is separated, who can reach it, and what happens when you ask for it back.
Free to start · no card · approved in 24h
How it is separated
Every workspace lives on its own subdomain and every record carries its workspace. Requests resolve from the host, and client-supplied workspace headers are stripped before anything reads them.
Twelve templates, around ninety-five separate permissions, and four visibility scopes: own records, a team, an org subtree, or everything. You edit them, not us.
Sign-ins, permission changes, exports, integration connects and revokes, and impersonation — with who, what and when, inside the product.
Sessions invalidated, password reset, mailbox and calendar disconnected, deals and tasks handed to a named successor — and the history stays.

Your data
HTTPS everywhere, passwords hashed with argon2, and OAuth tokens for your mailboxes and calendars encrypted at rest with a workspace key — never shown again after connecting.
Attachments live in object storage, addressed by content hash and served through short-lived signed links rather than a public URL that keeps working after you revoke it.
Reports export to file and the REST API returns every object your key is scoped to. There is no "contact us to get your data out" step.
A deletion request removes rows and the attachments behind them, including the ones in object storage. The request path is published and works for people who are not customers.
The assistant obeysthe same permissions.
It reads only what the employee it acts for is allowed to read. Memory is split into client-safe and internal, and the split is enforced. Every run logs its tools, tokens and cost. Outside AI tools reach the CRM read-only, and only if you enable it per person.
No certificationwe do not hold.
We are not SOC 2 or ISO 27001 certified and will not imply otherwise. Single sign-on today means Google; SAML is not implemented. Two-factor authentication is on the roadmap, not in the product. If procurement needs any of these, tell us before you sign.
Send us yoursecurity questionnaire.
An engineer answers it, not a form. If the answer is "not yet", it will say so.
