Skip to content

Security & Compliance ​

Data Security ​

Multi-Tenant Architecture ​

  • Each organization's data is completely isolated
  • Separate database schema per tenant
  • No cross-tenant data access possible
  • Tenant identified by unique ID in every request

Encryption ​

  • In transit: All data encrypted via HTTPS/TLS 1.3
  • At rest: Database encryption enabled
  • Passwords: Bcrypt hashed (not stored in plain text)
  • API tokens: Encrypted storage with secure rotation

Authentication ​

  • JWT-based authentication — Secure token-based login
  • Token expiry — Access tokens expire (configurable)
  • Refresh tokens — Seamless session renewal
  • Password requirements — Minimum 8 characters, configurable complexity

Access Control ​

  • Role-Based Access Control (RBAC) — Granular permissions per module
  • Field-Level Security — Hide sensitive fields from certain roles
  • Record-Level Security — Users see only their own or team's data
  • Hierarchy-Based Access — Managers see team data, reps see own data

Data Privacy ​

Data Ownership ​

  • Your data belongs to you
  • ZenTraq processes data only for providing the service
  • No data sharing with third parties without consent
  • Full data export available at any time

Data Retention ​

  • Active data retained as long as account is active
  • Deleted records purged after 30 days
  • Account deletion removes all data permanently
  • Backup data retained for 90 days post-deletion

GDPR Compliance (for applicable regions) ​

  • Right to access — Export all personal data
  • Right to erasure — Delete individual records or entire account
  • Consent tracking — Opt-in management for WhatsApp/Email
  • Data portability — Export in standard formats (CSV, JSON)

WhatsApp Compliance ​

  • Opt-in required before messaging
  • Opt-out honored immediately
  • Consent tracked with timestamp, source, and method
  • Message templates reviewed by Meta for compliance

User Security ​

Password Policy ​

Configure in Settings → Security:

  • Minimum length (default: 8 characters)
  • Require uppercase, lowercase, numbers
  • Password expiry (force reset every X days)
  • Prevent password reuse (last N passwords)
  • Account lockout after X failed attempts

Session Management ​

  • Active sessions visible in profile
  • Log out from all devices remotely
  • Session timeout after inactivity (configurable)
  • Single session or multi-session option

User Activity Logs ​

Track what users do:

  • Login/logout events
  • Record create/edit/delete
  • Bulk operations
  • Settings changes
  • Export actions
  • Permission changes

API Security ​

API Authentication ​

  • Bearer token (JWT) required for all API calls
  • Tenant ID header required for multi-tenant routing
  • Rate limiting to prevent abuse
  • IP allowlisting (optional)

Webhook Security ​

  • Verify tokens for incoming webhooks (WhatsApp, payment)
  • HTTPS only for webhook endpoints
  • Request signature validation

Infrastructure Security ​

Hosting ​

  • Hosted on DigitalOcean (SOC 2 certified infrastructure)
  • Region: India (BLR1) for data residency
  • Automatic backups (daily)
  • Redundant storage

Network Security ​

  • Firewall rules restrict access
  • Load balancer with DDoS protection
  • Service-to-service communication encrypted
  • No direct database access from internet

Monitoring ​

  • 24/7 health monitoring
  • Automatic alerts on anomalies
  • Performance monitoring
  • Error tracking and alerting

Compliance Features for Business ​

Audit Trail ​

Every action is logged:

  • Who did what, when, from where
  • Record changes tracked (old value → new value)
  • Immutable audit logs (cannot be edited)
  • Exportable for compliance audits
  • Export specific records or entire entities
  • Filter by date range for legal holds
  • Communication logs (emails, WhatsApp metadata)
  • Activity history with timestamps

Approval Workflows ​

For regulated processes:

  • Require manager approval before certain actions
  • Multi-level approval chains
  • Complete approval history
  • Rejection reasons documented

Best Practices ​

For Admins ​

  • Review user access quarterly — Remove unnecessary permissions
  • Enable 2FA (when available) — Extra login security
  • Monitor activity logs — Watch for unusual patterns
  • Set up IP restrictions — For sensitive operations
  • Regular password rotation — Enforce password changes
  • Export critical data monthly — Business continuity backup

For Users ​

  • Don't share credentials — Each user gets their own account
  • Log out on shared devices — Don't leave sessions active
  • Report suspicious activity — Notify admin immediately
  • Use strong passwords — Unique to this CRM, not reused
  • Respect data access — Only access records you need

ZenTraq CRM — Built for every industry.