Security & Compliance
Data Security
Multi-Tenant Architecture
- Each organization's data is completely isolated
- Separate database schema per tenant
- No cross-tenant data access possible
- Tenant identified by unique ID in every request
Encryption
- In transit: All data encrypted via HTTPS/TLS 1.3
- At rest: Database encryption enabled
- Passwords: Bcrypt hashed (not stored in plain text)
- API tokens: Encrypted storage with secure rotation
Authentication
- JWT-based authentication — Secure token-based login
- Token expiry — Access tokens expire (configurable)
- Refresh tokens — Seamless session renewal
- Password requirements — Minimum 8 characters, configurable complexity
Access Control
- Role-Based Access Control (RBAC) — Granular permissions per module
- Field-Level Security — Hide sensitive fields from certain roles
- Record-Level Security — Users see only their own or team's data
- Hierarchy-Based Access — Managers see team data, reps see own data
Data Privacy
Data Ownership
- Your data belongs to you
- ZenTraq processes data only for providing the service
- No data sharing with third parties without consent
- Full data export available at any time
Data Retention
- Active data retained as long as account is active
- Deleted records purged after 30 days
- Account deletion removes all data permanently
- Backup data retained for 90 days post-deletion
GDPR Compliance (for applicable regions)
- Right to access — Export all personal data
- Right to erasure — Delete individual records or entire account
- Consent tracking — Opt-in management for WhatsApp/Email
- Data portability — Export in standard formats (CSV, JSON)
WhatsApp Compliance
- Opt-in required before messaging
- Opt-out honored immediately
- Consent tracked with timestamp, source, and method
- Message templates reviewed by Meta for compliance
User Security
Password Policy
Configure in Settings → Security:
- Minimum length (default: 8 characters)
- Require uppercase, lowercase, numbers
- Password expiry (force reset every X days)
- Prevent password reuse (last N passwords)
- Account lockout after X failed attempts
Session Management
- Active sessions visible in profile
- Log out from all devices remotely
- Session timeout after inactivity (configurable)
- Single session or multi-session option
User Activity Logs
Track what users do:
- Login/logout events
- Record create/edit/delete
- Bulk operations
- Settings changes
- Export actions
- Permission changes
API Security
API Authentication
- Bearer token (JWT) required for all API calls
- Tenant ID header required for multi-tenant routing
- Rate limiting to prevent abuse
- IP allowlisting (optional)
Webhook Security
- Verify tokens for incoming webhooks (WhatsApp, payment)
- HTTPS only for webhook endpoints
- Request signature validation
Infrastructure Security
Hosting
- Hosted on DigitalOcean (SOC 2 certified infrastructure)
- Region: India (BLR1) for data residency
- Automatic backups (daily)
- Redundant storage
Network Security
- Firewall rules restrict access
- Load balancer with DDoS protection
- Service-to-service communication encrypted
- No direct database access from internet
Monitoring
- 24/7 health monitoring
- Automatic alerts on anomalies
- Performance monitoring
- Error tracking and alerting
Compliance Features for Business
Audit Trail
Every action is logged:
- Who did what, when, from where
- Record changes tracked (old value → new value)
- Immutable audit logs (cannot be edited)
- Exportable for compliance audits
Data Export for Legal
- Export specific records or entire entities
- Filter by date range for legal holds
- Communication logs (emails, WhatsApp metadata)
- Activity history with timestamps
Approval Workflows
For regulated processes:
- Require manager approval before certain actions
- Multi-level approval chains
- Complete approval history
- Rejection reasons documented
Best Practices
For Admins
- Review user access quarterly — Remove unnecessary permissions
- Enable 2FA (when available) — Extra login security
- Monitor activity logs — Watch for unusual patterns
- Set up IP restrictions — For sensitive operations
- Regular password rotation — Enforce password changes
- Export critical data monthly — Business continuity backup
For Users
- Don't share credentials — Each user gets their own account
- Log out on shared devices — Don't leave sessions active
- Report suspicious activity — Notify admin immediately
- Use strong passwords — Unique to this CRM, not reused
- Respect data access — Only access records you need
