Built to be trusted with your pipeline.
Multi-tenant isolation, an append-only audit trail, and OWASP-aligned defenses — because your leads, quotes and customer data deserve more than a login screen.
Every tenant runs in its own walled garden.
Isolation enforced at the platform level
- Every query is scoped by tenant at the platform layer, not left to application code to get right
- No shared database rows and no cross-tenant leakage by design
- Isolation is structural, not a checkbox toggled per customer
Access matches your org chart
- Role-based permissions down to individual features and actions
- Data scoping by branch, team or assignment — reps see only what they own
- Export and bulk-action rights restricted per role
- Admins can audit exactly who can see or touch what
Every action is logged. Nothing is edited after the fact.
Full append-only audit trail
- Who, what, when and where — logged for every action across the platform
- The trail is admin-readable and cannot be edited or deleted, even by admins
- TLS 1.2+ in transit and encryption at rest on MongoDB Atlas
Built to OWASP ASVS / Top-10 standards
- Bcrypt password hashing — passwords are never stored in plain text
- Server-side validation on every input, not just client-side checks
- CSP and security headers, rate limiting, and CSRF protection
- Secure, HttpOnly, SameSite cookies; no secrets ever shipped to the client
No grey-market shortcuts.
Official-channel-only stance
- Meta’s official WhatsApp Business API only — no unofficial gateways that risk a number ban
- DLT-registered SMS routes, not backdoor bulk senders
- Card payments run through Razorpay/Cashfree; card data never touches EZCRM’s servers
Your data is portable, not hostage
- Full export to XLSX/CSV, any time, for any module
- Demo-form and trial data is never sold or shared with third parties
- Leave with your data intact, if you ever choose to
Built on managed, multi-node infrastructure.
Infrastructure that doesn’t have a single point of failure
- MongoDB Atlas multi-node clusters, not a single database instance
- Daily backups with point-in-time recovery
- Maintenance windows are scheduled and announced in advance, not surprise downtime
Uptime you can verify
- 99.9% uptime over the trailing 12 months
- Status and incident history available on request
- No black-box infrastructure — ask, and we’ll show you
Found a vulnerability? We want to hear about it.
security@ezcrm.in
Report security issues directly to our security team. We acknowledge every report within 48 hours and work directly with researchers to verify and fix issues before they’re disclosed publicly.
Security questions, answered.
Is my data really isolated from other tenants?
Yes. Isolation is enforced at the platform level — every query is scoped to your tenant automatically, not left to individual application code to get right. There are no shared database rows between customers.
Do you sell or share data collected through demo or trial forms?
No. Demo-form and trial data is never sold or shared with third parties. It’s used only to set up and support your account.
Where is data hosted and backed up?
On MongoDB Atlas multi-node clusters, with daily backups and point-in-time recovery. Data is encrypted at rest and in transit (TLS 1.2+).
How do I report a security vulnerability?
Email security@ezcrm.in. We acknowledge every report within 48 hours and work directly with researchers to verify and fix issues before public disclosure.
Do you have a completed security questionnaire I can review?
We’re happy to walk through one. Our architecture is aligned to OWASP ASVS / Top-10 practices — email security@ezcrm.in with your questionnaire and we’ll turn it around quickly.
Have a security questionnaire?
Send it to security@ezcrm.in — we typically respond within 48 hours.
