InnHub CRM is built to manage partnerships and handle sensitive business relationships. Below is an overview of how we protect the data.
All data is encrypted in transit using TLS 1.2 or higher. Data at rest is encrypted at the storage layer. No sensitive information is ever transmitted or stored in plain text.
Every user account requires multi-factor authentication (TOTP) and a strong password. Access to data is enforced at the database level — each user can only read and write records that belong to their workspace.
All write operations are recorded in a tamper-evident audit log. Logs capture who performed an action, what was changed, and when — supporting accountability and incident review.
The application is hosted on enterprise-grade cloud infrastructure with SOC 2 Type II and ISO 27001 certified providers. Automated backups run daily with point-in-time recovery.
Errors and anomalies are captured in real time. Any unexpected behaviour is immediately notified and followed by a defined incident response process to investigate and remediate promptly.
Only the data is stored required to operate the CRM. Data is never sold or shared with third parties for advertising. You can request a full export or deletion of your workspace data at any time.
The CRM Assistant uses the Claude API by Anthropic to process natural-language queries. When you ask a question, your query and the relevant CRM data are sent to Anthropic's API for processing. Anthropic does not store API inputs or use them for model training (per their API data usage policy). Data is processed in-memory during the request and discarded after the response. Conversation history is stored exclusively in your own Supabase database — not at Anthropic. The AI cannot access data beyond what is returned by the CRM's own query tools, and all write operations require explicit user confirmation before execution.
Have a security question or concern? security@innhub-crm.ch
Privacy enquiries? privacy@innhub-crm.ch