Security & Compliance at Ivorycom
Ivorycom is built for teams that answer to auditors, regulators, and enterprise security reviews. Tenant data is isolated at the database layer, every change is written to an immutable audit ledger, access is governed by cryptographically signed policy, and privacy rights — consent, data export, and erasure — are first-class, self-service capabilities. Below is exactly how it works, and exactly where our compliance program stands.
Trust snapshot
Core controls at a glance
Tenant isolation
RLS (FORCE)
Audit trail
Append-only
Transport security
TLS 1.2+
Encryption at rest
AWS KMS
Security enforced in the architecture, not just the app.
Each control below is live in production today. They are designed so that confidentiality and integrity hold even when application logic is bypassed.
Tenant isolation at the database
Every tenant's data is isolated at the database layer with PostgreSQL Row-Level Security in FORCE mode — enforced on every single query by the database itself, not just by application code. A request can only ever see the rows that belong to its own tenant, even if application logic were bypassed.
Immutable audit ledger
An append-only, integrity-protected audit trail records every create, update, and delete across the platform. Entries cannot be altered or back-dated. Retention is set per plan, and records are legal-hold aware — a hold freezes the relevant trail from expiry until the matter is released.
Signed access control
Role-based and field-level security are evaluated from cryptographically signed (ed25519) policy bundles, so the rules that govern who can read or write each field are tamper-evident in transit and at rest. Administrators can dry-run any change with a built-in policy simulator before it takes effect.
Encryption & Bring Your Own Key
Data is encrypted in transit with TLS 1.2+ and at rest with AWS KMS. Business and Enterprise tenants can Bring Your Own Key (BYOK): register your own AWS KMS key so that DSAR export bundles and stored files are encrypted under your key, under your control — revoke it and the protected data becomes unreadable.
Privacy & GDPR rights
Consent management gates every marketing send. A one-click Data Subject Access Request exports all personal data across every service — including the audit trail — and right-to-erasure cascades across the platform within 24 hours. Legal hold and statutory-retention handling for financial records (GDPR Art. 17(3)(b)) are built in, all self-serve from the in-app Trust Center.
99.9% uptime SLA, independently monitored
Business and Enterprise plans carry a 99.9% monthly availability SLA backed by service credits. Uptime is measured by AWS Route 53 health checks that probe the production surfaces from multiple regions — independent of our own deploy pipeline — and is tracked on a live availability dashboard. Enterprise adds a named technical account manager and a one-hour P1 response target.
Privacy & data rights, self-service
Powered by the Ivorycom Trust Center
EU data residency
New tenants can optionally pin their data to the EU (eu-west-1), keeping records inside the region to meet data-residency obligations. Residency is chosen at tenant creation.
Hardened cloud infrastructure underneath every feature.
Ivorycom runs on AWS with defense-in-depth controls across the network, runtime, and secrets layers.
Where our compliance program stands today.
We believe security claims should be precise. Here is exactly what is true right now.
NIST SP 800-53 rev 5 (FedRAMP Moderate baseline)
Ivorycom aligns to NIST SP 800-53 rev 5 (FedRAMP Moderate baseline); our control inventory and System Security Plan are maintained continuously as we prepare for FedRAMP authorization.
Security reviews & enterprise questionnaires
Contact our team for security reviews, enterprise questionnaires, data-processing agreements, and details on any control described on this page.
Security
security@ivorycomcrm.com
Privacy
privacy@ivorycomcrm.com
Responsible disclosure
Researchers may report vulnerabilities to us in good faith. Include a description, reproduction steps, and supporting evidence — we will acknowledge and work with you.
Report a vulnerability