Skip to content
Security & trust

CRM data security, in plain English.

How LiftUp keeps your leads, posts and settings apart from every other customer, who on your team and ours can see them, and what gets logged. We list what is built and what is not yet. Our own lead pipeline runs on the same controls.

The short answer

Is my CRM data secure with LiftUp?

For the controls small teams check first, yes. Every query is scoped to your organisation, API keys are stored hashed, sign-in supports TOTP two-factor codes, and Growth and Enterprise keep an audit log of changes. What LiftUp does not have yet: a SOC 2 report, ISO 27001 or SAML sign-in. This page lists what is built, what is not, and how to report a problem.

1. Multi-tenant data isolation

LiftUp is multi-tenant. Each customer is an organisation, and every record it owns carries that organisation's ID. The application adds the ID to every database query through a global scope. It is not a filter in the interface that a user can remove.

Inside your organisation, each website or app is a product with its own rotatable API key, lead inbox, blog, custom fields and webhooks. Products share your team, your roles and your bill.

2. Hashed API keys and signed webhooks

  • API keys are hashed before they are stored. You see a key once, when you create it, and you can rotate it per product.
  • Webhook payloads are signed with HMAC SHA-256, so your endpoint can check that a request came from LiftUp.

3. Sign-in: 2FA and Google SSO

  • Two-factor authentication with time-based codes (TOTP) from any authenticator app.
  • Enterprise admins can enforce 2FA for everyone in the organisation.
  • Sign in with Google on Enterprise.
  • SAML and Microsoft sign-in are not available.

4. Role-based access control

Each user in your organisation gets one built-in role. The role decides which modules a person can open and whether they can change anything.

  • Admin: full control of the organisation.
  • Operations Manager: CRM, content and settings.
  • Sales Manager: leads, pipeline and assignments.
  • Content Manager: blog, editorial workflow and AI writing.
  • HR Manager: career and hire inboxes, and candidates.
  • Read Only: dashboards and reports, with no changes.

Global search (Ctrl/Cmd + K) applies the same permissions, so it never returns a record your role cannot open.

5. Audit log

LiftUp records changes to leads, blog posts, products, staff accounts and organisation settings in an audit log. You see it as an activity feed on the dashboard.

The audit log is included on Growth and Enterprise. Enterprise keeps a longer history.

Webhooks have their own delivery log, so you can see what LiftUp sent to your systems and whether it arrived.

6. Access by LiftUp staff

A small number of LiftUp operators hold a platform-admin role that can see across organisations. We use it to run the service and answer support requests.

Email [email protected] if your review needs our staff-access policy.

7. Hosting and backups

  • LiftUp is a hosted service. There is nothing to install.
  • Traffic reaches the app through Cloudflare.

Ask us for hosting and backup details during a demo.

8. AI features and your data

When you use Content AI or Image AI, the text or prompt you submit is sent to our AI provider to generate the result. The style analyzer reads your published posts to learn your brand voice.

AI usage is metered per organisation and shown on a usage dashboard.

9. Data export

  • Every plan can export leads as CSV.
  • Enterprise can export the full organisation dataset at any time.

10. Payments

Payments in USD and INR go through Razorpay, including UPI AutoPay for INR.

11. GDPR, DPDP and certifications

Our Privacy Policy explains that LiftUp acts as your processor for lead data you store. It also lists the kinds of processors we use.

LiftUp does not hold a SOC 2 report or an ISO 27001 certificate today.

Enterprise customers can ask us to sign a data-processing agreement.

12. Report a vulnerability

If you think you have found a security issue, email [email protected] with a description and steps to reproduce.

Give us reasonable time to fix the issue before you disclose it, and do not access or change data that is not yours.

Questions about security in general go to the same address: [email protected].

Fact sheet

CRM security checklist, by plan.

What each plan includes today, and what LiftUp does not offer yet. Use it to fill in your vendor security review.
LiftUp security controls by plan
FreeStarterGrowthEnterprise
Isolation & keys
Tenant isolation on every queryIncludedIncludedIncludedIncluded
Hashed, rotatable API key per productIncludedIncludedIncludedIncluded
HMAC SHA-256 signed webhooksNot includedNot includedIncludedIncluded
Sign-in & access
Google SSO + enforced 2FANot includedNot includedNot includedIncluded
SAML SSONot includedNot includedNot includedNot included
Records & data
Audit logNot includedNot includedIncludedLonger history
Data exportLead CSVLead CSVLead CSVFull org export
Assurance
SOC 2 reportNot includedNot includedNot includedNot included
ISO 27001 certificateNot includedNot includedNot includedNot included

FAQ

CRM security questions, answered.

How is my data kept separate from other customers?

Each customer is an organisation, and every record carries its organisation ID. The application scopes every database query to your organisation through a global scope. Isolation is enforced by the application on every query, not only in the interface. Inside your organisation, each website or app is a product with its own API key.

Can LiftUp staff see my data?

Yes, a small number of LiftUp operators can, through a platform-admin role we use to run the service and answer support requests. Email us if your review needs our staff-access policy.

What roles and permissions can I give my team?

Each user gets one built-in role: Admin, Operations Manager, Sales Manager, Content Manager, HR Manager or Read Only. Sales roles work in leads and the pipeline, content roles work in the blog and AI tools, and Read Only can view dashboards and reports without changing anything. Global search applies the same permissions.

What does the audit log record?

It records changes to leads, blog posts, products, staff accounts and organisation settings, and shows them as an activity feed on your dashboard. The audit log is included on Growth and Enterprise. Enterprise keeps a longer history. Webhook deliveries have their own log, showing what LiftUp sent to your endpoints.

Can I require 2FA or Google sign-in for my team?

Every user can protect their account with TOTP codes from an authenticator app. On Enterprise, an admin can enforce 2FA for the whole organisation and turn on Google sign-in. SAML and Microsoft sign-in are not available.

Does LiftUp have SOC 2, ISO 27001 or a DPA?

LiftUp has no SOC 2 report or ISO 27001 certificate today. Our Privacy Policy explains that LiftUp acts as your processor for lead data you store. Enterprise customers can ask us to sign a data-processing agreement.

Where is my data hosted, and how is it backed up?

LiftUp is a hosted service with nothing to install, and traffic reaches the app through Cloudflare. Every plan can export leads as CSV, and Enterprise can export the full organisation dataset at any time. Ask us for hosting and backup details during a demo.

Why is LiftUp on a .sh domain? Is it safe?

.sh is the country-code domain of Saint Helena, Ascension and Tristan da Cunha. Developer tools like it because .sh is also the shell-script file extension. The domain itself has no effect on security.

Security review on your list?

Book a demo and bring your security questions.