Your whole security posture on a single page.
10 tabs, 7 live status cards that fetch in real time. Not a theater of green badges: each card shows the real state — ok, watch, or info.
We tell you what's done. And what's not.
Most SMB CRMs pin badges they don't have. Us, the Compliance page shows the real state. That's exactly what the CAI wants to see.
- 2FA TOTP + 8 single-use recovery codes
- FIDO2 / WebAuthn passkeys (real physical key)
- Immutable audit log — RLS blocks update & delete
- Brute-force protection: 5 tries, 30 min penalty
- IP allow-list by CIDR, per organization
- Login alerts + « That wasn't me » button
- Tracked sessions, revocable (all but the current one)
- Suspended employee = sessions cut by a DB trigger
- SIEM export CEF / JSON / syslog (Splunk, Datadog…)
- 72h breach counter wired to a cron (Law 25 art. 95)
- IP always hashed (sha256 + salt), never in clear
- Written CVSS patch SLA: 7 / 30 / 90 days, measured
- Law 25 privacy impact assessment done (July 3, 2026), available on request
- Sensitive secrets encrypted: email tokens, telephony credentials
- Generalized at-rest encryption: rolling out
- SOC 2 / ISO 27001 certification: none to date
- Geo-IP blocking by country: not yet
An audit log you can't erase.
Database rules block any change and any deletion of the log —even for a compromised admin. Every action keeps its per-field diff: who, when, from which IP (hashed), old value → new. Two sources merged: modified entities + logins/logouts.
Three safety nets so you never lock yourself out.
2FA TOTP, real FIDO2 passkey (physical key or biometrics), and 8 single-use recovery codes. You can force 2FA by role: sensitive routes (Security, Billing, Team, Integrations, Admin) refuse access without a second factor.
Brute-force blocked, IPs filtered, logins watched.
A suspended employee = logged out in a second.
You see all your connected devices and you can revoke « all other sessions » at once. And above all: when you suspend a member, a database trigger cuts their sessions instantly — no waiting for their token to expire.
Your logs in your SIEM. The 72h breach that counts itself.
SIEM export per organization in CEF / JSON / syslog format — pluggable into Splunk, Datadog or Elastic with no external dependency. Plus an hourly watchdog that alerts if a serious incident isn't reported to the regulator within 72h (Law 25 art. 95).
We patch within a written deadline, not « soon ».
Everything about security.
Lock down your CRM.
14 days free, no card. Turn on 2FA, your IP list and your audit log in 5 minutes.
We'll show you the honest Compliance page in a 45-sec demo.
