Security
How Capto CRM protects your data: encryption, access controls, secrets handling, and incident response.
Encryption
All data is encrypted in transit using TLS and at rest using industry-standard encryption.
Access controls
Access to production systems and customer data is restricted to authorized personnel and protected by role-based permissions.
Secrets handling
API keys, tokens, and credentials are stored in a dedicated secrets manager and never committed to source control.
Secrets are rotated regularly and access is logged and audited.
Authentication
User authentication is handled through a trusted identity provider with support for strong password policies and session management.
Data isolation
Every record in our database is scoped by a business_id so one business can never see another business's data.
Monitoring
We continuously monitor our systems for unusual activity and respond quickly to any potential incidents.
Vulnerability disclosure
If you discover a security vulnerability, please report it to security@usecapto.com. We appreciate responsible disclosure and will respond promptly.
Questions
For more details, see our Privacy Policy and Terms of Service, or contact us.