← The SoliCRM blog

Security and GDPR, built in

A CRM holds the names, emails, phone numbers and history of everyone you do business with. Protecting them is not an option you buy later; in SoliCRM it is part of every plan.

Platform · 2026-10-03
Security and GDPR, built in

Your data, on its own, in France

Each company has its own database, on servers at OVHcloud in Strasbourg (ISO 27001). Backups run every night and are kept fourteen days. The public Status page shows, at any time, whether the database answers and how fast, whether the last backup is less than 30 hours old, and whether outgoing mail is set up.

Signing in safely

  • Passwords of at least 12 characters, stored with Argon2id — never in a form that can be read back.
  • Brute force stopped twice: an account locks for 30 minutes after 10 failed attempts (and its owner is told by email), and an address is limited to 15 attempts every 5 minutes.
  • Two-factor authentication with any authenticator app — 1Password, Google Authenticator, Authy…: scan the QR code on the Security page, or type the key. A code can only be used once.
  • Single sign-on through OpenID Connect or SAML 2.0 — Okta, Microsoft Entra ID, Google Workspace, Keycloak, Auth0… Each connection serves your email domains; you can enforce it for those domains (admins keep a password, so a broken identity provider never locks everyone out) and create users on their first sign-in.

Who sees what

Users are admins or members, and each has a manager who sees their team's records. Per object, records are public, read-only for others, or private. Custom fields can be reserved to admins, and page layouts differ per profile.

When someone leaves, Deactivate signs them out everywhere at once and keeps their records — and frees their seat.

A history that cannot be quietly rewritten

Changes to key fields — a deal's amount or stage, a case's status, an account's owner — are recorded with who, when, and the old and new values. Each entry is chained to the previous one with a SHA-256 hash: Setup shows "Chain intact", or the exact entry where the chain breaks if anyone tampered with it.

GDPR, the practical part

The regulation asks for things a CRM can actually do for you:

  • Consents per purpose — marketing emails, marketing calls, sharing with partners —, each with when, how and by whom it was given or withdrawn, and the full history.
  • Access requests: a complete export of everything about a person — the record, their consents, activities, history, deals and cases — in one file.
  • Erasure: a person's details are cleared and replaced by "Erased …", their activities emptied, while the business records the law requires you to keep — deals, invoices for ten years — stay.
  • Retention periods: leads never converted and untouched for the number of months you choose are erased automatically every night.
  • A register of every request — access, erasure, consent, retention — that records what was done without storing the personal data again.

Contracts in order

Your terms, privacy policy, data processing agreement (GDPR article 28) and list of sub-processors — OVHcloud, Cloudflare, Resend, Stripe — are published and kept up to date, and changes are announced thirty days ahead. The services you choose to connect yourself — Google or Microsoft, Stripe, Yousign, a phone system, an e-invoicing platform, an AI provider — are listed separately, so you always know who processes what.

In short

  • One database per company, in France, backed up nightly, with a public status page.
  • Strong passwords, lockouts, two-factor authentication, OIDC and SAML single sign-on.
  • Roles, managers, private records and admin-only fields.
  • A hash-chained history of key fields.
  • Consents, exports, erasure, retention and a register of requests for GDPR.

Back to the start: SoliCRM, feature by feature.

Try SoliCRM with your own data.

Keep reading