Security attestation
SOC 2 Type II
Hosting
AWS (via Supabase)
Encryption
AES-256 + TLS 1.3
Identity controls
RBAC, MFA, SSO
Compliance
SOC 2 Type II
Independent assurance is a core control for enterprise procurement review.
Controls
Updated and monitoredInfrastructure security
- Cloud infrastructure on AWS
- Network protections and hardened services
- Backups and recovery readiness
- Environment-level access controls
Organizational security
- Role-based access control
- Multi-factor authentication
- Least-privilege access management
- Security process ownership
Product security
- Encryption at rest and in transit
- Authentication and session controls
- Audit-oriented event tracking
- Ongoing hardening of workflows
Internal security procedures
- Operational security reviews
- Incident response workflows
- Periodic control validation
- Change and access governance
Data and privacy
- Data classification aware practices
- Privacy policy and DPA support
- Subprocessor transparency
- Customer request handling
Compliance & Data Privacy
Compliance frameworks and privacy standards relevant to customers in the US, Canada, the EU, and India.
SOC 2 Type II
Soor LLC (HelloGrowthCRM) completed an independent SOC 2 Type II examination covering Feb–Jun 2025. The full report is available under NDA — email sales@hellogrowthcrm.com
CCPA
California Consumer Privacy Act. US-based customers have full data subject rights including access, deletion, and portability. Data Processing Addendum available.
HIPAA
HelloGrowthCRM can support HIPAA-compliant deployments for healthcare customers with a signed BAA. Contact sales for BAA terms.
ADA / WCAG 2.1 AA
Our web application targets WCAG 2.1 Level AA for US accessibility compliance. Accessibility statement at /legal/accessibility.
Data Hosting & Residency
Your CRM data is hosted on AWS (via Supabase) with AES-256 encryption at rest, TLS 1.2+ in transit, and automated daily backups. For enterprise or dedicated deployments with specific residency requirements (US, EU, or India), contact us to confirm the region for your account.
GDPR
EU General Data Protection Regulation. We support data subject rights (access, rectification, erasure, portability) and offer a Data Processing Addendum for EU/UK customers.
DPDPA 2023 (India)
India's Digital Personal Data Protection Act. We follow DPDPA-aligned data-handling practices for Indian customers, including consent, purpose limitation, and data-principal rights. DPA available on request.
PDPL (UAE)
UAE Personal Data Protection Law. HelloGrowthCRM supports UAE customers under PDPL requirements — including data-subject rights, cross-border transfer safeguards, and controller obligations. Relevant for businesses operating in Dubai, Abu Dhabi, and across the UAE.
India Data Residency (on request)
For tenants with DPDPA data-localisation requirements, India-region (AWS Mumbai / ap-south-1) data residency is available for enterprise and dedicated deployments on request. Contact us to scope an in-country deployment for your customer records, WhatsApp conversation logs, and contact data.
Questions about security?
Request trust documentation, ask compliance questions, or start a security review.
Agentic AI Safety
HelloGrowthCRM AI agents operate within a configurable safety framework. Every agent action is logged, reversible, and bounded by per-agent limits you configure.
Three autonomy levels
Autonomous, Supervised, and Assistive. You choose the level per agent — from fully hands-off to recommendation-only.
Per-agent action limits
Set daily call limits, spend caps, and volume thresholds. Agents cannot exceed configured boundaries.
Full audit trail
Every agent action is logged with timestamp, agent identity, and data changed. Immutable record for compliance review.
One-click pause
Any agent can be paused instantly from admin settings without affecting other automations or workflows.
PII masking
Raw contact data can be masked from agent-accessible logs and AI client responses via MCP scope settings.
Human-in-the-loop gates
Supervised agents stage actions for human approval before committing. No autonomous action without explicit configuration.
How HelloGrowthCRM protects sales data day to day
A CRM holds the most commercially sensitive information a sales team owns: every contact, every quoted price, every WhatsApp thread with a prospect. Soor LLC, the company behind HelloGrowthCRM, completed a SOC 2 Type II examination covering the February–June 2025 observation window — meaning an independent auditor tested that our security controls actually operated over time, not just that policies existed on paper.
All traffic between your browser, the mobile app, and our servers is encrypted in transit with TLS, and data is encrypted at rest on the underlying storage. The application database runs on Supabase-managed Postgres with row-level security policies, so tenant isolation is enforced by the database engine itself rather than only by application code. Inside your workspace, role-based access control determines what each rep, manager, and admin can see — a field rep can work their own pipeline without browsing the whole company's deal values.
For Indian customers, our data-handling practices align with the Digital Personal Data Protection Act, including the Section 20-relevant obligations around processing children's data and consent. Details on exercising access, correction, and erasure requests are on the data rights page; security researchers can report issues through the vulnerability disclosure programme.
Security questions buyers ask before signing
Straight answers to the questions IT reviewers and founders raise most during evaluation. Anything not covered here can be asked directly — we respond to security questionnaires as part of every enterprise evaluation.
- Where is my CRM data stored?
- Customer records live in Supabase-managed Postgres databases hosted on AWS infrastructure, with row-level security (RLS) policies enforcing tenant isolation at the database layer. Each workspace's contacts, deals, call logs, and WhatsApp conversation history are scoped to that workspace — queries from one tenant cannot read another tenant's rows even at the SQL level. Hosting region details for your account are confirmed during onboarding or security review.
- How are backups handled?
- Databases are backed up on an automated schedule through our managed Postgres provider, with point-in-time recovery capability so data can be restored to a recent state if an operational error occurs. Backup retention windows and recovery objectives are documented in the SOC 2 Type II report, which procurement teams can request under NDA via sales@hellogrowthcrm.com.
- Who inside HelloGrowthCRM can access customer data?
- Access follows least-privilege principles. Production data access is limited to a small set of engineers who need it for support or incident response, gated behind multi-factor authentication and role-based access control. Routine support work happens through admin tooling that logs every access event, and access grants are reviewed periodically as part of the SOC 2 control set.
- What happens if there is a security incident or breach?
- We operate a documented incident-response workflow: detect, contain, assess impact, remediate, and notify. Affected customers are informed in line with our contractual and statutory obligations, including DPDPA requirements for Indian data principals. If a researcher finds a vulnerability first, our disclosure process at /legal/vulnerability-disclosure gives them a direct, safe-harbour channel to report it.
- Can I export or delete my data?
- Yes. Workspace admins can export contacts, deals, and activity data at any time, and account deletion requests are honoured through the process described on our data rights page. Under DPDPA Section 20-aligned practices, Indian customers can exercise access, correction, and erasure rights; EU/UK and California customers have equivalent rights under their respective frameworks.
Running a vendor assessment? This trust center packages the documents procurement usually needs — SOC 2 report request, DPA, and subprocessor list — in one place. Or start a free trial and evaluate the access controls hands-on.
A practical security checklist for evaluating any CRM
If you are comparing vendors, four questions separate real security posture from a badge on a homepage. First, ask for the audit type and observation window: a SOC 2 Type II report tests that controls operated over months, while a Type I only confirms they existed on one day. Second, ask how tenant isolation is enforced — at the database layer, or only in application code. Third, ask who can access production data and how that access is logged and reviewed. Fourth, ask what the incident notification commitment actually is, in writing.
HelloGrowthCRM's answers to all four are on this page, and the same standard applies across the product — including the mobile apps for iOS and Android, where sessions use the same encrypted transport and role-based permissions as the web app. For the commercial side of an evaluation, see pricing; for how data flows through the sales workflow itself, the features overview shows what reps, managers, and admins each can see and do.