Trust & Security

CRM security and GDPR compliance built into every account

Security in CRMLeaf isn't a separate module bolted on top - ownership-scoped permissions, two-factor authentication, an audit log and GDPR consent tools are part of the same platform every plan runs on.

  • Free trial
  • No credit card
  • Free onboarding
2FA · TOTP app
Audit log · on
GDPR consent
MCP · no delete tools

Recent activity

  • Priya Shah updated Deal #1042 · stage

    09:42
  • MCP · Claude updated Contact #318 · phone, email

    09:47

Layer 01

Access Control

Roles decide which pages a person can open. Ownership-scoped permissions go further, deciding which records they see once they're there - none, only their own, only what they added, both, or all. Condition-based RBAC guardrails enforce the dependencies a permission grid should always have, refusing a save that doesn't make sense rather than silently applying it.

Ownership scoping (none/owned/added/both/all)RBAC guardrailsAdmin / employee / client roles

Built in

  • Entrust roles plus custom fine-grained permissions
  • Ownership-scoped visibility per module
  • Guardrails that refuse incoherent permission saves

Layer 02

Authentication

Sign-in supports email/password, Google and Microsoft social login, and two-factor authentication through a TOTP app or email - so a compromised password alone isn't enough to reach an account that has 2FA switched on.

Google & Microsoft loginTwo-factor authenticationEmail-verification cutoff

Built in

  • Email/password login plus Google and Microsoft social login and signup
  • Two-factor authentication (TOTP app or email)
  • An email-verification cutoff date that grandfathers existing users

Layer 03

Audit Trail

An audit and recent-activity log tracks who did what across the account, so a question about who changed a record has an answer. The same discipline extends to AI-assistant activity through the MCP server: the audit trail records who acted, the token, the action, the record and the field names touched - never the field values.

Audit / recent-activity logCovers MCP (AI assistant) actions too

Built in

  • Audit and recent-activity logging across the account
  • Field-name-level (never field-value) logging of AI-assistant actions via MCP

Layer 04

GDPR & Consent

Public GDPR consent pages let a lead or contact register consent directly, with an administrator able to approve or reject requests - built into the same lead and deal workflow rather than a separate compliance tool.

Public consent pagesAdmin approve / reject

Built in

  • GDPR / consent tools with public consent pages
  • Admin approval workflow on consent requests

Layer 05

Backup & Uptime

Database backup and an in-app updater are part of the core platform, so keeping the system current and recoverable isn't left to a customer's own IT team.

Database backupIn-app updater

Built in

  • Database backup
  • In-app updater for platform releases

Layer 06

AI Assistant Access

When you connect Claude, Cursor, VS Code Copilot or another Model Context Protocol client to CRMLeaf, it calls the API as you, forwarding your own personal access token - so it's bound by the same multi-tenant scoping and permissions you already have, nothing more. The MCP server exposes no delete tools, by design.

Scoped personal access tokensNo delete tools by designBound by your own permissions

Built in

  • Personal access tokens with a 30-day default expiry, read-only or read-write
  • MCP server calls the API as the connecting user, never with elevated access
  • No delete tools available through MCP, regardless of the user's own permissions

Layer 07

Add-on Security

Add-on

For accounts that need a stricter security posture, the CyberSecurity add-on adds email and IP blacklists and login-expiry policies, and the Subdomain add-on gives a tenant its own white-label host.

Email / IP blacklistsLogin-expiry policiesWhite-label subdomain

Built in

  • CyberSecurity - email/IP blacklists and login-expiry policies (add-on)
  • Subdomain - white-label host routing per tenant (add-on)
FAQ

Common questions about security in CRMLeaf

See CRMLeaf's security model in a live demo

Bring your team's actual permission structure and we'll show you how ownership-scoped access maps to it.

CRMLeaf - Security is part of the CRMLeaf platform.