Effective 25 May 2026
Security
How we protect your pipeline data, from infrastructure to incident response.
CRM Brain processes recruiting pipeline data on behalf of agencies. We treat that data as sensitive business information and apply layered controls to keep it secure. This page explains what those controls are so you can make an informed decision about trusting us with your data.
Infrastructure
The CRM Brain application is hosted on Vercel with EU data residency enabled. All primary database and file storage runs on Supabase within AWS eu-central-1 (Frankfurt). Your data does not leave the EU for storage purposes.
- Encryption at rest: AES-256 encryption applied to all data stored in Supabase.
- Encryption in transit: All connections between your browser, the CRM Brain servers, and our sub-processors use TLS 1.2 or higher. Unencrypted HTTP connections are rejected.
- EU data residency: Primary data storage is in Frankfurt. Vercel CDN edge caching for static assets operates globally, but no personal data is cached at the CDN layer.
Access Controls
Every database query in CRM Brain is filtered by your team ID using Supabase Row-Level Security policies. These policies are enforced at the database layer, not just in application code, which means a bug in the application cannot expose another team's data.
- Row-level security: Enforced on all 10 database tables. No query can return rows belonging to a different team.
- Multi-factor authentication: Available for all user accounts. Roveva Solutions staff with production access are required to use MFA.
- API keys and secrets: All service credentials are stored as environment secrets in Vercel and Supabase. They are never committed to version control or logged.
- Least privilege: Production database access is restricted to the minimum permissions required for each service component.
HubSpot Integration
CRM Brain connects to your HubSpot account via OAuth 2.0. The integration is strictly read-only: we request only the minimum scopes needed to read your pipeline data (contacts, deals, companies, and associated activities). We never write to, modify, or delete any record in your HubSpot account.
You can revoke CRM Brain's access at any time from your HubSpot Connected Apps settings. On revocation, no further data will be pulled, and your existing data will be deleted within 30 days.
AI Data Handling
To generate lead scores and pipeline insights, CRM Brain sends subsets of your deal and contact data to the Claude API, operated by Anthropic PBC. The following protections apply:
- No model training: Anthropic does not use API input or output to train its models. This is contractually guaranteed under our Anthropic Data Processing Addendum.
- Minimum data: We send only the fields needed to generate a useful response (deal name, stage, value, key activity summaries). We do not send attachments, full email bodies, or candidate CVs.
- Prompt log retention: We retain AI prompt and response logs for up to 90 days for quality assurance. Logs are stored in EU Frankfurt and are accessible only to Roveva Solutions staff.
- Transfer basis: Data sent to Anthropic (US) is covered by Standard Contractual Clauses under GDPR Art. 46(2)(c).
Backups and Recovery
- Daily automated backups: Supabase performs daily automated backups of the entire database.
- Point-in-time recovery: Supabase supports point-in-time recovery, allowing restoration to any point within the retention window.
- EU residency for backups: Backup data remains within the EU (Frankfurt) and is subject to the same encryption and access controls as primary data.
Vulnerability Disclosure
We welcome good-faith security research. If you have found a potential vulnerability in CRM Brain, please email security@crm-brain.com with a description of the issue, steps to reproduce it, and any supporting evidence.
- We will acknowledge your report within 48 hours.
- We aim to patch critical issues within 7 days of confirmation.
- We will keep you informed of progress and credit your report if you wish.
- We do not pursue legal action against researchers who follow this policy and do not exfiltrate, modify, or destroy data during their research.
Incident Response
In the event of a personal data breach affecting your data, CRM Brain will notify you within 72 hours of becoming aware of the incident, as required by GDPR Article 33. The notification will include: the nature of the breach; the categories and approximate volume of data affected; the likely consequences; and the steps being taken to contain and remediate the incident.
We maintain an internal incident response plan that is reviewed annually. Any incident affecting personal data is logged and assessed regardless of whether external notification is legally required.
Compliance
- GDPR (EU 2016/679): CRM Brain processes personal data in accordance with GDPR. A Data Processing Agreement (DPA) is available for all customers at crm-brain.com/dpa.
- TTDSG / §25 TTDSG: Cookie storage and access to terminal equipment follows German telecommunications data protection law. Consent is collected before non-essential cookies are set.
- Sub-processor DPAs: All US-based sub-processors (Anthropic, Resend, Vercel, Stripe, HubSpot) are covered by Standard Contractual Clauses and individual data processing agreements.
Questions
Security questions: security@crm-brain.com
General data protection queries: hello@crm-brain.com
Roveva Solutions, Sandstücken 9, 25421 Pinneberg, Germany