It's the question we get most often when we talk about Oracle: 'If an AI has access to all my client data, how do I know my information is safe?' It's a legitimate and important question. Here are concrete answers, without the needless technical jargon.
Built-in Law 25 compliance
The first fundamental guarantee: toncrm.io has carried out a privacy impact assessment (PIA) and documents it for your clients who request it. You don't have to handle that obligation on your own.
Why does it matter? Under Law 25, you have the obligation to protect your clients' personal information and to make sure any transfer outside Quebec is covered by a PIA. Most American CRMs leave you to carry out that assessment yourself — a complex legal task that most small and mid-sized businesses have neither the time nor the expertise to do properly.
The principle of least privilege
Oracle has access to the data it needs to do its job — but only that data. It doesn't have access to passwords, to clients' full payment information, or to documents marked as confidential according to the settings you define.
You control what Oracle can see and what it can do. In the security settings, you can define data zones that Oracle can't access: certain categories of notes, certain clients, certain types of documents.
End-to-end encryption
The communications between your device and our servers are encrypted in transit (TLS 1.2+): even if someone intercepted them, they'd be unreadable. Sensitive secrets (email connection tokens, telephony credentials) are encrypted, off-site backups are encrypted, and generalized encryption at rest is being rolled out.
Conversations with Oracle are encrypted the same way. The notes you give it by voice, the commands you type, and the answers it gives you — all of that is protected.
Human access to your data
toncrm.io employees don't have access to your client data in the course of their normal operations. Access to client data is reserved for technical support situations you have explicitly authorized, and every access is logged and auditable.
We don't sell your data. We don't use your clients' data to train AI models. Your data is yours — we're just the infrastructure that hosts it and processes it according to your instructions.
Law 25 compliance
toncrm.io is designed to make your Law 25 compliance easier, not to complicate it. We give you tools to document your data-handling policies, manage your clients' access or deletion requests, and identify privacy risks.
If one of your clients asks what information you hold about them — which they have the right to do under Law 25 — you can generate a complete report in a few minutes directly from toncrm.io.
Mandatory multi-factor authentication
Every toncrm.io account requires two-factor authentication for logins from new devices. That means even if someone gets your password, they can't access your account without the second factor (your phone).
Oracle specifically can be configured to require an extra confirmation before certain sensitive actions: sending bulk emails, deleting data, or changing critical settings. You decide the level of validation required.
Security audits and monitoring
toncrm.io keeps a complete audit log of every action performed by Oracle and by the users on your account. If you want to check what Oracle has done over the last 30 days — which data it accessed, which actions it carried out — you can consult that log at any time.
Automatic alerts notify you if unusual behavior is detected: logins from unusual countries, multiple failed access attempts, or access to unusual volumes of data.
Your rights as the owner of the data
If you cancel your subscription, you have the right to export all your data in a standard format (CSV, JSON) before your account closes. Your data isn't held hostage. After the 90-day retention period following cancellation, all your data is deleted from our servers in a secure and unrecoverable way.
Security isn't a bonus that toncrm.io tacks on — it's a foundation. Because your clients' trust depends on how you handle their information, and the trust you place in toncrm.io depends on how we protect your data.