Security & trust
Your customer data, protected by design.
AutomateNexus CRM is built for teams that can't compromise on security. Encryption everywhere, enterprise access control, AI governance, and data you own outright, so you can adopt agents without giving up control.
- In transit
- TLS 1.2+
- At rest
- AES-256
- On every account
- 2FA
- Plus row-level security
- RBAC



Six layers, working together.
Security isn't a setting you turn on. It's how the whole platform is built, from the database to the agents to the export button.
01
Data protection
Every byte is encrypted in transit with TLS 1.2+ and at rest with AES-256. Secrets and API keys are stored in an isolated vault, never in plaintext.
- TLS 1.2+ in transit
- AES-256 at rest
- Isolated secrets vault
- Encrypted backups
02
Access control
Google and Microsoft sign-in, two-factor you can require, roles, and database-level workspace isolation keep the right people in the right records, and everyone else out.
- Sign in with Google, Microsoft or LinkedIn
- Role-based access control (RBAC)
- Row-level security
- 2FA on every account
- Admin impersonation with audit logging
03
Compliance posture
We operate to SOC 2-aligned controls and build GDPR-ready by default. Your data is hosted in the United States.
- SOC 2-aligned practices
- GDPR-ready
- Hosted in the United States
- DPA published
04
Reliability
Redundant infrastructure, continuous monitoring, and a 99.9% uptime SLA on Agency keep your pipeline available when you need it.
- 99.9% uptime SLA (Agency)
- Continuous monitoring
- Redundant infrastructure
- Automated failover
05
AI governance & BYOK
Bring your own model keys, keep humans in the loop on sensitive actions, and review every agent decision in a complete audit trail.
- Bring your own model keys (BYOK)
- Human-in-the-loop approvals
- Full agent audit trail
- Your data never trains third-party models
06
Data ownership
Your data is yours. Export everything, from contacts and deals to notes and history, anytime, in open formats, with no lock-in or exit fees.
- One-click full export
- Open formats (CSV / JSON)
- Full API access
- No exit fees
Built to the standards your buyers audit for.
| Standard | Status |
|---|---|
| SOC 2 | Type II in progress |
| GDPR | Compliant |
| CCPA | Compliant |
| DPA | Published |
Security documentation is shared under NDA. Our data processing addendum is published and applies to every customer.
Talk to sales to start that processYour data is yours. We just keep it safe.
Clear commitments, in plain language. No fine print designed to confuse.
- 01
We never sell your data
Your CRM records and customer data are never sold, shared, or used to train third-party models.
- 02
You own your records
Export everything, anytime, in open formats. Leaving is as easy as joining.
- 03
Least-privilege access
Our team accesses customer data only when you request support, logged and time-boxed.
- 04
Hosted in the United States
Your records, files and backups are stored in the US. Choosing another hosting region isn't available yet.
- 05
Sub-processors disclosed
We send the current list of every sub-processor we use to any customer who asks, and give notice before adding one.
- 06
Breach notification
A clear, fast incident process: you're notified promptly if anything affects your data.
The short version.
Least privilege by default
Row-level security and granular roles mean people only ever see the records they're meant to.
Governed AI
Every agent action is logged, reversible where it matters, and gated behind approvals on anything sensitive.
Yours to take
No lock-in. Export the whole workspace in open formats whenever you want, no questions asked.
- 09:02Karrie searched the CRM: 1 deal, 3 activities
- 09:02Draft written from the deal's own history
- 09:03Held for approval. Nothing sent.
The questions security teams ask first.
Yes. All data is encrypted in transit with TLS 1.2 or higher and encrypted at rest with AES-256. Backups are encrypted as well, and secrets such as API keys are held in an isolated vault rather than in your records.
Every plan includes sign-in with Google, Microsoft or LinkedIn, role-based access control, and two-factor authentication your organisation can require for everyone. SAML single sign-on from your identity provider is available on your verified domain, with directory provisioning from Okta and Microsoft Entra ID.
Not certified. We operate to SOC 2-aligned controls and are GDPR-ready by default, and we're happy to share our security documentation under NDA. Our data processing addendum (DPA) is published and applies to every customer; ask if you need a signed copy.
Yes. BYOK is supported on every plan. Karrie and the agent team run on your own provider keys, so you keep cost control and your data stays under your governance. Your data never trains third-party models.
It leaves with you. Export everything, from contacts and deals to notes, files and history, anytime in open formats, or pull it via the API. There are no exit fees and no lock-in.
Always. When an admin uses impersonation for support, every action is recorded in an immutable audit log with the actor, target, timestamp, and change. Nothing happens to your data without a trace.
Bring agents in without giving up control.
Talk to our team about your security requirements, request documentation, or start a trial in your own environment.