Built on AWS · governed by signed policy

Security & Compliance at Ivorycom

Ivorycom is built for teams that answer to auditors, regulators, and enterprise security reviews. Tenant data is isolated at the database layer, every change is written to an immutable audit ledger, access is governed by cryptographically signed policy, and privacy rights — consent, data export, and erasure — are first-class, self-service capabilities. Below is exactly how it works, and exactly where our compliance program stands.

Row-Level Security (FORCE)Immutable audit ledgerBYOK encryptionNIST SP 800-53 rev 5

Trust snapshot

Core controls at a glance

Tenant isolation

RLS (FORCE)

Audit trail

Append-only

Transport security

TLS 1.2+

Encryption at rest

AWS KMS

How Ivorycom protects your data

Security enforced in the architecture, not just the app.

Each control below is live in production today. They are designed so that confidentiality and integrity hold even when application logic is bypassed.

Tenant isolation at the database

Every tenant's data is isolated at the database layer with PostgreSQL Row-Level Security in FORCE mode — enforced on every single query by the database itself, not just by application code. A request can only ever see the rows that belong to its own tenant, even if application logic were bypassed.

Immutable audit ledger

An append-only, integrity-protected audit trail records every create, update, and delete across the platform. Entries cannot be altered or back-dated. Retention is set per plan, and records are legal-hold aware — a hold freezes the relevant trail from expiry until the matter is released.

Signed access control

Role-based and field-level security are evaluated from cryptographically signed (ed25519) policy bundles, so the rules that govern who can read or write each field are tamper-evident in transit and at rest. Administrators can dry-run any change with a built-in policy simulator before it takes effect.

Encryption & Bring Your Own Key

Data is encrypted in transit with TLS 1.2+ and at rest with AWS KMS. Business and Enterprise tenants can Bring Your Own Key (BYOK): register your own AWS KMS key so that DSAR export bundles and stored files are encrypted under your key, under your control — revoke it and the protected data becomes unreadable.

Privacy & GDPR rights

Consent management gates every marketing send. A one-click Data Subject Access Request exports all personal data across every service — including the audit trail — and right-to-erasure cascades across the platform within 24 hours. Legal hold and statutory-retention handling for financial records (GDPR Art. 17(3)(b)) are built in, all self-serve from the in-app Trust Center.

99.9% uptime SLA, independently monitored

Business and Enterprise plans carry a 99.9% monthly availability SLA backed by service credits. Uptime is measured by AWS Route 53 health checks that probe the production surfaces from multiple regions — independent of our own deploy pipeline — and is tracked on a live availability dashboard. Enterprise adds a named technical account manager and a one-hour P1 response target.

Privacy & data rights, self-service

Powered by the Ivorycom Trust Center

Consent management before every marketing send
One-click DSAR export across every service
Right-to-erasure cascading within 24 hours
Audit-trail data included in DSAR exports
Legal hold to suspend deletion for active matters
Statutory retention for financial records (Art. 17(3)(b))
Bring Your Own Key (BYOK) for exports and files
Optional EU (eu-west-1) data residency

EU data residency

New tenants can optionally pin their data to the EU (eu-west-1), keeping records inside the region to meet data-residency obligations. Residency is chosen at tenant creation.

Optional · eu-west-1
Platform security

Hardened cloud infrastructure underneath every feature.

Ivorycom runs on AWS with defense-in-depth controls across the network, runtime, and secrets layers.

AWS infrastructure with private networking
AWS WAF in front of the platform
99.9% availability SLA, independently monitored (Business / Enterprise)
Container image vulnerability scanning
Least-privilege IAM roles
Secrets stored in AWS Secrets Manager
Separate production and non-production environments
Compliance program

Where our compliance program stands today.

We believe security claims should be precise. Here is exactly what is true right now.

NIST SP 800-53 rev 5 (FedRAMP Moderate baseline)

Ivorycom aligns to NIST SP 800-53 rev 5 (FedRAMP Moderate baseline); our control inventory and System Security Plan are maintained continuously as we prepare for FedRAMP authorization.

NIST SP 800-53 rev 5FedRAMP authorization in progress
We do not currently hold a SOC 2 report, ISO 27001 certification, or a completed FedRAMP authorization. We will state plainly when that status changes — we do not claim certifications we have not earned.

Security reviews & enterprise questionnaires

Contact our team for security reviews, enterprise questionnaires, data-processing agreements, and details on any control described on this page.

Security

security@ivorycomcrm.com

Privacy

privacy@ivorycomcrm.com

Responsible disclosure

Researchers may report vulnerabilities to us in good faith. Include a description, reproduction steps, and supporting evidence — we will acknowledge and work with you.

Report a vulnerability