Security Policy
Last Updated: June 26, 2026
1. Infrastructure & Hosting
NeetiCRM services and databases are hosted on Amazon Web Services (AWS). We utilize secure AWS data centers equipped with state-of-the-art physical security, including round-the-clock surveillance, biometric access gates, and fire suppression systems.
Our primary hosting servers and database instances are located in the Asia Pacific (Mumbai, India) region. This ensures minimal latency for local operations and complies with data localization guidelines.
2. Data Encryption
We secure customer information and lead data through multiple layers of encryption:
- Data in Transit: All communication between your web browser and NeetiCRM servers is encrypted using industry-standard Transport Layer Security (TLS 1.3) protocols. This prevents eavesdropping or tampering.
- Data at Rest: All customer data stored inside our databases, lead indices, and S3 file storage (including voice call recordings, media attachments, and logs) is encrypted at rest using Advanced Encryption Standard (AES-256) cryptographic keys.
- API Integrations: Connections with Meta APIs (WhatsApp Cloud, Facebook Ads) and payment gateways use secure HTTPS tokens and signature verifications.
In Plain English
3. Account Security & Authentication
We employ robust security practices to protect user accounts:
- Password Hashing: User passwords are encrypted on our servers using the salted bcrypt hashing algorithm. We never store passwords in plain text.
- Two-Factor Authentication (2FA): We support and encourage Multi-Factor Authentication (MFA) via TOTP authenticator apps to provide an extra layer of security during login.
- Session Management: Active user tokens automatically expire after period of inactivity. We employ strict Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) protections inside our front-end framework.
4. Backups & Disaster Recovery
To protect against hardware failures or regional disasters:
- Automated Backups: Full database backups are captured automatically every 24 hours. These backups are encrypted and stored in isolated storage configurations.
- Retention: Backup images are retained for a rolling period of 30 days before automatic deletion.
- Redundancy: Our database systems run in Multi-AZ (Availability Zone) setups. If a primary database node fails, standby systems automatically take over in real time without data loss or manual intervention.
In Plain English
5. Employee & Administrative Access
We maintain strict access controls within our organization:
- NeetiCRM employees do not have access to your CRM database, lead details, or voice transcripts unless explicitly requested by you for technical troubleshooting or support.
- Our operations staff use secure VPN connections and MFA to access backend servers.
- All system access is logged and audit trials are regularly analyzed for anomalies.
6. Security Incident Reporting
We take security vulnerabilities seriously. If you discover a vulnerability or suspect an account compromise:
- Do not exploit the vulnerability or share details publicly.
- Email us immediately at security@neeticrm.com with detailed reproduction steps.
- We will review your submission and respond within forty-eight (48) hours. We appreciate responsible disclosure.