Security

How Capto CRM protects your data: encryption, access controls, secrets handling, and incident response.

Encryption

All data is encrypted in transit using TLS and at rest using industry-standard encryption.

Access controls

Access to production systems and customer data is restricted to authorized personnel and protected by role-based permissions.

Secrets handling

API keys, tokens, and credentials are stored in a dedicated secrets manager and never committed to source control.

Secrets are rotated regularly and access is logged and audited.

Authentication

User authentication is handled through a trusted identity provider with support for strong password policies and session management.

Data isolation

Every record in our database is scoped by a business_id so one business can never see another business's data.

Monitoring

We continuously monitor our systems for unusual activity and respond quickly to any potential incidents.

Vulnerability disclosure

If you discover a security vulnerability, please report it to security@usecapto.com. We appreciate responsible disclosure and will respond promptly.

Questions

For more details, see our Privacy Policy and Terms of Service, or contact us.