Where your information lives
Your workspace runs on managed cloud infrastructure operated by established suppliers. We do not keep servers in an office or under a desk, and we do not copy your workspace onto anybody’s laptop. Traffic between your browser and the product is encrypted, and the database and file storage behind it are encrypted where they sit.
If your business needs to know the country a particular workspace’s information is held in, ask us and we will tell you in writing. We would rather answer that properly than print a map on a marketing page.
Who can see it
Every piece of information in the product carries the workspace it belongs to, and every read is filtered by that workspace inside the database itself — not only in the screens on top of it. A person who is not a member of your workspace cannot read a row of it, even with a link. A member who has not finished signing in the way your workspace requires cannot read it either.
Inside a workspace, what someone sees is decided by their role and by who owns the record. Owners and admins set the roles; a role can be given or refused each individual permission, and a member can be given an exception on top of their role. Leaders see the people who report to them. Some parts of the product can be gated behind training or paperwork before anyone may open them.
Our own people: everyone who runs the product signs in with a second step, always. When one of our support staff needs to look inside your workspace to diagnose a problem, they open a support visit. A visit needs a written reason, has a fixed end and stops working on its own when it arrives. It starts read-only, and the database itself refuses changes until writing is turned on as a separate step with its own reason. While it is open, a banner sits across every screen they see. Every visit — who, when, why, whether they could change anything, and when it ended — is listed for your owners and admins under Settings, and appears in your workspace’s activity log.
Separately, the product’s background jobs — sending your reminders and notifications, building an export you asked for — run with an administrative key that is not tied to a person, and each job filters to one workspace at a time. Our internal screens show what we need to run your account (who belongs to the workspace, which modules it holds, how much storage it uses), never the records, messages or files inside it, and there is no tool for reading many workspaces’ information at once.
How someone gets in
People sign in with an email address and a password. New members join by invitation from an owner or admin; an invitation is a single-use link that expires. Public pages — a proposal to sign, a customer portal, a booking page — are reached through a one-off link tied to the thing it opens, and nothing else.
- Two-step sign-in. Anyone can add a code from an authenticator app to their sign-in, with single-use backup codes for a lost phone. An owner can require it for everyone in the workspace, with a grace period; after it, a member without it cannot open the workspace until it is set up.
- Single sign-on. A workspace can sign its people in through its own identity provider (SAML 2.0 — for example Microsoft Entra ID, Okta or Google Workspace). The owner proves they own the email domain first, tests the connection, and can then make it the only way in for that domain and let new people from it join with a chosen role. Our team switches each connection on after checking it.
- Session and password rules. An owner can set how long a sign-in lasts, sign people out after a period without activity, and require a longer minimum password, which applies whenever a member chooses one and at their next sign-in.
- Signing people out. An owner can see every device their members are signed in on and sign one person, or everyone, out.
Forms and links that anyone on the internet can reach are rate limited. We store a one-way fingerprint of the requesting address for that, never the address itself.
What is recorded
- An activity log. Work across the product writes to one log: what happened, who did it, what it was about, and when. Owners and admins can search it by person, area, record and date, and export it as a spreadsheet.
- Sign-ins. Successful and failed sign-ins, two-step codes, backup codes used, password changes and sign-outs are recorded against the person, with the device and country. Owners see them under Settings → Security.
- Security changes. Changes to sign-in rules, single sign-on, exports and closing the workspace are all in the log.
- Anything sent or received on your behalf. Email you send from a record, texts, information posted into your workspace by another system, and every message we send out to another system — each with what came back.
- Information sent in by your own tools. Every post made to one of your workspace’s incoming addresses is logged with what was sent and what we did with it. Reads made with a workspace key are not logged one by one yet.
Connection secrets — the keys and passwords you paste in when connecting an outside service — are encrypted before they are stored and are never shown again after you save them, not to you and not to us in the screens.
Backups and keeping things running
The database is backed up automatically by the supplier that runs it, and files you delete sit in a recovery window before they are permanently removed, so an accidental deletion is usually undoable from inside the product.
Our own checks test the app, the database, signing in, email sending, file storage and background work every five minutes. The results, 90 days of history and every incident we post are on the status page, and our team is alerted when a check fails twice in a row.
That page is a record of what we measured, not a promise. We do not publish an uptime or recovery-time commitment, and we do not have a signed service level agreement on the shelf. If you need one, that is a conversation, not a download.
Getting your information out
It is yours, and you can take it with you. A workspace owner can export the whole workspace in one step from Settings → Export and Delete: every table as spreadsheet files and as structured data, plus every stored file, in one archive. It is built in the background, and the owner is emailed a download link that expires after seven days and only works for the owner, signed in. Every export and every download is recorded. Connection passwords, keys and other secrets are left out.
Any saved list and the reporting tools also export to a spreadsheet, and a workspace key lets another system read the information held by the add-on modules you use.
Deleting things
Admins can delete records in bulk from inside the product, and can undo an import that went wrong. Deleted files are recoverable for a window and then permanently removed.
A workspace owner can close the workspace from Settings → Export and Delete. It closes for everyone straight away, and 14 days later everything in it — records and stored files — is deleted from the live system; the owner can change their mind until then. Copies inside routine backups age out with those backups rather than disappearing the same afternoon.
Trying it, and what happens after
When a trial finishes, everything you put in is kept exactly as it was, and that part's screens are locked until you switch it back on. A whole-workspace export still includes it. Nothing is deleted and nothing is charged automatically.
Opening a workspace does not ask for payment details, so there is nothing sitting on file waiting to charge you.
What we do not claim
We hold no security certification. We are not SOC 2 audited, not ISO 27001 certified, not HIPAA compliant and not PCI certified, and nobody here will imply otherwise on a call. Card payments, where you take them through the product, are handled by a specialist payment provider and card numbers never reach us.
We use a small number of outside suppliers to run the product — hosting, sign-in, email delivery, text messaging, payments. We keep a current list of who they are and what each one does, and we will send it to you on request or attach it to a contract. We do not print suppliers’ names on our marketing pages.
We do not sell your information, we do not share it with advertisers, and we do not use what is inside your workspace to build anything we sell to somebody else.
Telling us about a problem
If you think you have found a security problem, tell us through the contact page with “Security” in the first line. Describe what you found and how you found it, and give us a way to reach you. We will confirm we have it, tell you what we think, and tell you when it is fixed.
Please do not run automated scans against the product, do not try to reach another workspace’s information, and do not test anything that could take the service down for other people. We do not run a paid bug bounty. We will not threaten anybody who reports something in good faith and stays within those lines.
Who you are dealing with
CRM Stride is operated by Rampart Holdings LLC. Questions about this page, about a contract, or about anything above can go through the contact page.
Procurement asking for something specific?
Send us the questionnaire. We will answer every line, including the ones where the answer is “no, and here is what we do instead”.
Contact us
