Aller au contenu principal
FIG 0.0 · SECURITY

Security and Law 25,without lying.

2FA, physical key, an audit log we don't erase, IP allow-list, sessions, SIEM export, 72h breach counter. Plus a Compliance page that tells you what's done — and what isn't yet.

Free 14-day trial

No credit card required.

toncrm.io Security page: 2FA, sessions, audit log, Law 25 compliance
FIG 0.1 · THE HUB

Your whole security posture on a single page.

10 tabs, 7 live status cards that fetch in real time. Not a theater of green badges: each card shows the real state — ok, watch, or info.

Overview
7 posture cards, each one live
2FA + recovery
TOTP, 8 single-use codes, passkeys
Active sessions
Your devices, revocable one by one
IP allow-list
CIDR allow-list per organization
Login alerts
« That wasn't me » in one click
Law 25 compliance
The real status, no cosmetic badge
Incidents
72h breach counter, art. 95
SIEM export
CEF / JSON / syslog to your tool
Audit log
Immutable, per-field diff
Backup
Reversible trash + DB export
FIG 0.2 · WHAT'S DONE · WHAT ISN'T

We tell you what's done. And what's not.

Most SMB CRMs pin badges they don't have. Us, the Compliance page shows the real state. That's exactly what the CAI wants to see.

Done, in prod
  • 2FA TOTP + 8 single-use recovery codes
  • FIDO2 / WebAuthn passkeys (real physical key)
  • Immutable audit log — RLS blocks update & delete
  • Brute-force protection: 5 tries, 30 min penalty
  • IP allow-list by CIDR, per organization
  • Login alerts + « That wasn't me » button
  • Tracked sessions, revocable (all but the current one)
  • Suspended employee = sessions cut by a DB trigger
  • SIEM export CEF / JSON / syslog (Splunk, Datadog…)
  • 72h breach counter wired to a cron (Law 25 art. 95)
  • IP always hashed (sha256 + salt), never in clear
  • Written CVSS patch SLA: 7 / 30 / 90 days, measured
  • Law 25 privacy impact assessment done (July 3, 2026), available on request
  • Sensitive secrets encrypted: email tokens, telephony credentials
Not yet — we show it
  • Generalized at-rest encryption: rolling out
  • SOC 2 / ISO 27001 certification: none to date
  • Geo-IP blocking by country: not yet
Why we write it: lying about a location or a badge is a legal risk under Law 25. Real compliance comes from a documented privacy impact assessment and declared transfers — not from a green sticker.
FIG 0.3 · AUDIT LOG

An audit log you can't erase.

Database rules block any change and any deletion of the log —even for a compromised admin. Every action keeps its per-field diff: who, when, from which IP (hashed), old value → new. Two sources merged: modified entities + logins/logouts.

vs the others: an editable audit log is a useless audit log. Here immutability is locked at the database level, not just « by convention ».
Deal edited · by Marie-Claude · 14:32
Status
QualifiedWon
Amount
8 000 $12 000 $
Owner
Marie-Claude Roy
Locked · 7-year retention · CSV export
2FA TOTP
6-digit code, standard app
FIDO2 passkey
Physical key or Face/Touch ID
8 recovery codes
Single-use, hashed, downloadable .txt
FIG 0.4 · ACCESS

Three safety nets so you never lock yourself out.

2FA TOTP, real FIDO2 passkey (physical key or biometrics), and 8 single-use recovery codes. You can force 2FA by role: sensitive routes (Security, Billing, Team, Integrations, Admin) refuse access without a second factor.

FIG 0.5 · THE PERIMETER

Brute-force blocked, IPs filtered, logins watched.

Brute-force
5 tries in 15 min from one IP → 30 min block. The IP hashed, never in clear, purged after 7 days.
IP allow-list
Allow-list by CIDR, per organization. Anti-lockout: the config page stays reachable even if you block yourself.
« That wasn't me »
New login from an unknown device → email + button. One click revokes the session and resets.
FIG 0.6 · SESSIONS

A suspended employee = logged out in a second.

You see all your connected devices and you can revoke « all other sessions » at once. And above all: when you suspend a member, a database trigger cuts their sessions instantly — no waiting for their token to expire.

MacBook · MontréalThis session
iPhone · MontréalRevoke
Windows · unknownRevoke
Incident · unauthorized access
72h — the counter runs on its own
SIEM export · last flush: 142 events
FIG 0.7 · ENTERPRISE

Your logs in your SIEM. The 72h breach that counts itself.

SIEM export per organization in CEF / JSON / syslog format — pluggable into Splunk, Datadog or Elastic with no external dependency. Plus an hourly watchdog that alerts if a serious incident isn't reported to the regulator within 72h (Law 25 art. 95).

vs the others: SIEM export and 72h breach tracking are rare in SMB CRMs — usually you need an enterprise add-on or a third-party tool.
FIG 0.8 · THE DETAILS THAT MATTER

We patch within a written deadline, not « soon ».

Measured patch SLA
Critical in 7 days, high in 30, medium in 90 — a cron measures it, not a soft promise.
IP never in clear
sha256 + salt on all security tables. An IP is personal data under Law 25 — we hash it.
7-year retention
Audit log kept 7 years by default (margin over the Law 25 minimum), then purged by cron.
FIG 0.9 · FAQ

Everything about security.

No — the infrastructure is in the European Union and we say so openly. What makes you Law 25 compliant is the privacy impact assessment, the declared out-of-Quebec transfers (art. 17) and encryption in transit — not a location in Canada.

No. Database policies block any update and any deletion, even for an administrator. Every action keeps its per-field diff: old value struck through in red, new one in green.

5 failures in 15 minutes from the same IP → login blocked for 30 minutes. The IP is hashed, never in clear, and automatically purged after 7 days.

Yes — real FIDO2 / WebAuthn passkeys, on top of 2FA and the 8 single-use recovery codes. Three safety nets so you never lock yourself out.

Not to date, and the Compliance page shows it as is. We document our policies, a measured patch SLA, continuous security review and a completed privacy impact assessment (July 3, 2026) rather than pinning a badge we don't have.

You choose the roles required to use 2FA in the settings. Sensitive routes (Security, Billing, Team, Integrations, Admin) refuse access without 2FA for those roles.
L'entrepreneur d'aujourd'hui
FIG 1.0 · GET STARTED

Lock down your CRM.

14 days free, no card. Turn on 2FA, your IP list and your audit log in 5 minutes.

Free 14-day trial

We'll show you the honest Compliance page in a 45-sec demo.

Essai gratuit 14 joursAppeler Clodyne

Ready to see toncrm.io for real? We show it to you set up for your trade.

Book a 15-minute demo — or start your free trial right away.

Free 14-day trial

No credit card · Setup done for you · French-language support

Features