Last updated: January 1, 2026

Security Policy

Security is foundational to Radius CRM. Here is how we protect your tenant and your subscribers' data.

AES-256

Encryption at rest

TLS 1.3

Encryption in transit

SOC 2

Type II audited

99.99%

Uptime SLA

1

Infrastructure

Radius CRM runs on enterprise-grade cloud infrastructure with the following controls:

  • Hosted in AWS (Mumbai + Singapore regions) with multi-AZ redundancy
  • Database encryption at rest using AWS KMS-managed AES-256 keys
  • Annual key rotation; per-tenant data encryption keys on Enterprise plans
  • DDoS protection via AWS Shield + Cloudflare
  • Web Application Firewall (WAF) with OWASP Top 10 rule set
2

Tenant isolation

Every tenant's data is logically isolated at the database layer. Each query is bound to the authenticated tenant ID — there is no shared table access across tenants.

  • Per-tenant row-level security (RLS) policies
  • Per-tenant database connection pooling
  • Backup snapshots are tenant-scoped and encrypted separately
3

Authentication & access

  • Passwords hashed with bcrypt (cost factor 12)
  • Optional 2FA via TOTP (Google Authenticator, Authy) — available on all plans
  • SSO via SAML 2.0 on Enterprise plans
  • Session tokens rotated on every login; idle timeout 30 min
  • Role-based access control (RBAC) with audit trail of every privileged action
4

Application security

  • OWASP-aligned secure development lifecycle
  • All inputs validated, output-encoded (Laravel built-in protection)
  • CSRF tokens on every state-changing request
  • Rate limiting on all public endpoints (60 req/min per IP)
  • SQL injection protection via parameterized queries (Eloquent ORM)
  • Content Security Policy (CSP) and HSTS headers
5

Operational security

  • Daily automated encrypted backups, retained 30 days
  • Quarterly DR drill — full restore from backup in < 4 hours
  • 24/7 monitoring with PagerDuty; mean time to acknowledge < 5 min
  • Centralized logging via Sentry + CloudWatch; 90-day retention
  • Principle of least privilege for all internal access
  • Background checks on all employees with access to production
6

Compliance

  • SOC 2 Type II — audited annually by an independent firm
  • GDPR — DPA available on request; sub-processor list maintained
  • India DPDP Act 2023 — compliant with data principal rights
  • PCI DSS — payment data handled only by certified processors (we never store card numbers)
7

Penetration testing

We engage independent third-party security firms to perform penetration tests quarterly. Critical and high-severity findings are remediated within 7 days.

Summary reports are available to Enterprise customers under NDA. Email security@radiuscrm.io to request one.

8

Responsible disclosure

We welcome reports from security researchers. If you discover a vulnerability, please email security@radiuscrm.io with a proof of concept and reproduction steps.

We commit to acknowledge within 24 hours and provide a remediation timeline within 5 business days. Valid reports may be eligible for our bug-bounty reward.

9. Contact

For security-related questions, vulnerability reports or to request our SOC 2 report:

Radius CRM Security Team

3rd Floor, Indiranagar Tech Park, Bengaluru 560038, India

security@radiuscrm.io

Report a vulnerability

We respond to security reports within 24 hours. Bug-bounty eligible.

security@radiuscrm.io