How we protect your customer data.
Closerr is a mobile-first CRM trusted by field sales teams in the UK merchant services industry. This page lays out our security posture, what we do today, what we're working towards, and who you can talk to if you have questions.
Security at a glance
Defence in depth, least-privilege access, and tenant data isolation are baked into the platform from the start.
Tenant isolation
Every database query is filtered by organisationId. Your data is never returned in a query for another customer.
Role-based access
Four roles per workspace — owner, admin, sales manager, sales rep — with enforced server-side authorisation on every action.
Encryption
AES-256 at rest and TLS 1.2+ in transit. HSTS enforced on every Closerr domain.
Authentication
SSO via Google Workspace, Microsoft Entra ID, and Apple. Email/password supported with bcrypt hashing.
Audit logging
Authentication, privileged actions, and webhook handling are logged. Logs retained for at least 90 days.
Backups
Continuous point-in-time recovery with 30-day retention. Restore tested quarterly.
Payments
All payment card data is handled by Stripe (PCI DSS Level 1). Closerr never stores or processes card numbers.
Patching
Critical vulnerabilities patched within 48 hours; high within 14 days. Dependencies scanned weekly.
Compliance & certifications
Where we are today, what's in flight, and what's on the roadmap. We don't claim certifications we don't have.
| Standard | Status | Notes |
|---|---|---|
| UK GDPR / Data Protection Act 2018 | Live | DPIA + ROPA register maintained. Data subject requests handled within 30 days. |
| PCI DSS — SAQ-A scope | Live | All card data captured by Stripe Elements. No PAN on Closerr infrastructure. |
| Cyber Essentials (UK NCSC) | Submission in flight | Target: certified within 60 days. Plus level targeted within 90 days of basic. |
| SOC 2 Type II | Audit roadmapped | Controls inventory in place today; full audit on the 12-month roadmap. |
| ISO 27001 | Under evaluation | Decision after SOC 2 completion. |
| Independent penetration test | Scheduled | First engagement scheduled within 90 days. Scope document available on request. |
Sub-processors
The third-party services that process Closerr customer data on our behalf. Customers are notified at least 30 days in advance of any change to this list.
| Sub-processor | Purpose | Region |
|---|---|---|
| Replit | Production hosting, managed PostgreSQL, object storage | US (underlying hyperscaler region per deployment) |
| Stripe | Subscription billing & payments (web) | UK / EU / US |
| RevenueCat | Mobile in-app subscription management | US |
| OpenAI | LLM inference (Closerr Assistant), voice transcription | US (no training on submitted data — enterprise terms applied) |
| Resend | Transactional email delivery | US |
| Calendar / Gmail integration (when customer connects), SSO | Global | |
| Microsoft | Outlook / Mail integration (when customer connects), SSO (Entra ID) | Global (EU residency where elected) |
| Apple | Sign in with Apple (SSO) | US |
Data handling
Plain-language answers to the questions customers actually ask.
Do you train AI on our data?
No. OpenAI is bound by enterprise terms that prohibit training on data submitted via the API. We don't train any model on customer data.
Where is our data stored?
Replit-managed PostgreSQL with regional selection at provisioning. UK / EU residency available on request.
Can we export our data?
Yes. CSV / JSON export available for every object type via the API and the in-app back-office. You always retain ownership.
What happens if we leave?
You can export everything before cancellation. After deletion, your data is purged within 30 days from primary storage and within 90 days from backups.
Who can access our data internally?
Production administrative access is time-boxed, MFA-protected, and logged. Quarterly access reviews confirm only authorised staff have any access.
What if there's a breach?
Confirmed material incidents are notified to affected customers and (where applicable) the ICO within 72 hours of confirmation. A full post-incident report follows within 14 days.
For procurement & security teams
Documents we can share under NDA on request.
- Pre-filled SIG Lite security questionnaire
- Pre-filled CAIQ Lite (Cloud Security Alliance) questionnaire
- Controls inventory mapped to NIST CSF 2.0, CIS Controls v8, and SOC 2 TSC 2017
- Information security policy + subsidiary policy pack (access control, incident response, data classification, encryption, patching, business continuity, acceptable use)
- Pen-test scope-of-work document
- Sub-processor register with DPA status per processor
- Data Processing Agreement template (UK GDPR Art 28 compliant)
Changelog
Material changes to our security posture or sub-processor list.
Talk to us
The fastest way to get a security question answered or to request our compliance documents under NDA.
closerr