Skyra CRM SEO & Growth Website Development Automation & AI WhatsApp Business API Email Automation Pricing WhatsApp templates Email templates Industries Integrations Blog About Contact Start free trial Log in to your workspace
Security

Your customer data, treated properly

A CRM holds the most sensitive commercial information a business has. Here is exactly how we protect it, and what you can verify for yourself.

Encryption

TLS 1.3 for everything in transit and AES-256 at rest, including backups. Encryption keys are rotated and managed separately from the data.

  • TLS 1.3, HSTS enforced
  • AES-256 at rest
  • Encrypted off-site backups
  • Separate key management

Access control

Permissions work at both role and record level, so a user sees the accounts they own or share, and only the fields their role permits.

  • Role and record-level permissions
  • Field-level visibility rules
  • Two-factor authentication
  • SSO and SAML on Business and above

Audit and monitoring

Every create, update, export and login is recorded in an append-only log that administrators can review and export.

  • Immutable audit log
  • Export and download tracking
  • Login and session history
  • IP allow-listing

Infrastructure

Hosted on tier-one infrastructure with isolated environments, automated patching and 24/7 monitoring.

  • Isolated production environments
  • Automated dependency patching
  • DDoS protection and WAF
  • 99.9% uptime commitment

Backups and recovery

Daily encrypted backups with 30-day point-in-time recovery, and a restore process we test rather than assume.

  • Daily automated backups
  • 30-day point-in-time recovery
  • Quarterly restore testing
  • Dedicated instance option

Data residency and rights

Choose where your data lives. Export it whenever you want, and have it deleted permanently when you ask.

  • India, Singapore or EU regions
  • Signed DPA on request
  • Full export at no charge
  • Verified deletion on request

Reporting a vulnerability

If you believe you have found a security issue in Skyra, email security@theeduera.com with enough detail to reproduce it. We acknowledge reports within one working day and will keep you updated until it is resolved.

Please do not run automated scanners against production, access data that is not yours, or disclose the issue publicly before we have had a reasonable chance to fix it. We do not take legal action against researchers who follow those principles.

Documents available on request

  • Data Processing Agreement (DPA)
  • Security questionnaire responses
  • Most recent penetration test summary
  • Sub-processor list and data flow diagram