Platform – Security

Security built into every layer.

From granular per-module permissions to two-factor authentication, SSO, data isolation and GDPR tools – EasyCRM protects your data and your team without compromise.

Access control

Granular permissions for every module

EasyCRM uses Spatie RBAC with team scoping. Each role has precisely defined permissions for every module – contacts, leads, pipeline, inbox, telephony, reports, billing and privacy. The organisation admin creates and edits roles directly in settings without any code change. Permissions are enforced on every HTTP request, so no team member can access data they are not entitled to.

  • Granular permissions per module (contacts, leads, pipeline, inbox, telephony, reports, billing)
  • Team scoping – each member sees only what belongs to them
  • Roles: admin, manager, salesperson, support – fully configurable
  • Role management directly in settings
  • Permissions enforced on every request

Authentication

Two-factor authentication and enterprise SSO

EasyCRM supports TOTP (time-based one-time passwords) via any authenticator app – Google Authenticator, Authy or 1Password. Recovery codes ensure access even if a device is lost. An admin can enforce 2FA for the entire organisation with a single toggle. For enterprise teams with an existing identity provider, SSO is available via SAML 2.0 (SP-initiated, ACS callback, metadata endpoint, JIT provisioning) or OIDC with PKCE and nonce and JWKS signature verification – compatible with Google Workspace, Azure AD and Okta. SSO is available on the Pro plan.

  • 2FA via authenticator app (TOTP)
  • Recovery codes for regaining access
  • Organisation can enforce 2FA for all members
  • SSO via SAML 2.0 (Pro) – JIT provisioning
  • SSO via OIDC + PKCE (Pro) – compatible with Google Workspace, Azure AD, Okta

Isolation & GDPR

GDPR and per-org data isolation

Every organisation has its own subdomain and all database queries are automatically scoped to `organization_id` – one customer will never see another's data. EasyCRM ships with GDPR tools built in: record consent per contact with a full change history, export all contact data as JSON at any time, or anonymise PII records on request. The audit log records every change in the system. ULID identifiers ensure numeric IDs never leak into URLs or the API. Webhooks (Meta, email, API) are verified by HMAC signature before processing.

  • Every organisation has an isolated, scoped database
  • GDPR: consent history, JSON data export, PII anonymisation
  • Audit log of every action
  • ULID identifiers – no numeric IDs in URLs or API
  • HMAC webhook verification (Meta, email, API)

What you get

Security that scales with your team

  • Every team member has exactly the access they need
  • 2FA protects every account even without an enterprise IdP
  • SSO integrates EasyCRM into your corporate identity (Pro)
  • Every organisation sees only its own data
  • GDPR tools available from day one
  • Customer consent recorded with a full change history
  • Audit log captures every change in the system

Frequently asked questions

Questions about EasyCRM security

It is not mandatory by default. Every user can enable it in their profile settings. The organisation admin can enforce 2FA for all team members.

EasyCRM supports SAML 2.0 (SP-initiated) and OIDC with PKCE. SSO is available on the Pro plan and works with most enterprise identity providers – Google Workspace, Azure AD, Okta and others.

Yes. Every organisation has its own subdomain and all database queries are automatically scoped to `organization_id`. One customer will never see another customer's data.

You can record consent for each contact including a full change history. A complete JSON export of all customer data is available at any time, as is PII record anonymisation on request.

Permissions are granular per module: contacts, leads, opportunities, activities, inbox, telephony, reports, billing and privacy. Each role can have different read and write permissions for every module.

Give your team the right access from day one

Register for free and configure roles, 2FA and GDPR tools right after sign-up.