NameCRM security
NameCRM holds what a service business cannot afford to leak: client records, emails, call recordings, contracts and invoices. This page explains how that information is protected, in plain words first, with the technical detail underneath for whoever checks it for you.
Every statement here describes how NameCRM works today. Where some information leaves Canada, we say so.
- Where your database and files are stored
- Canada
- Where your database and files are stored
- Automated test suites every change must pass
- 230+
- Automated test suites every change must pass
- Scripts loaded from outside servers
- 0
- Scripts loaded from outside servers
- In Trash before a deleted record is gone for good
- 30 days
- In Trash before a deleted record is gone for good
How it is protected
What keeps your data safe
Many small business tools load code from other companies' servers on every page, so a problem on one of those servers can reach every page that loads from it. NameCRM is built the other way, and every change to it is checked before it ships.
No code from outside servers
Every piece of code NameCRM runs in your browser comes from our own servers, at a version we chose and checked. Your browser refuses code from anywhere else.
Technical detailScripts are self hosted at exact, pinned versions, downloaded from the official npm registry with integrity checked, each with a Subresource Integrity hash so a changed copy is refused. A Content Security Policy blocks scripts from any other origin; in a real browser test, an injected outside script was blocked on every page.
Every change is checked before it ships
No change to NameCRM goes live until it passes automated checks. A change that tries to add code from an outside source is refused, and every code change carries a written security review.
Technical detailOver 230 automated test suites must pass before release. A supply chain check refuses any new third party script. A written security review is required on every code change.
Each account sees only its own data
The rules that decide who can read what are enforced by the database itself, so one account cannot read another account's data.
Technical detailRow level security (RLS) policies in the Postgres database.
Two-step sign-in for staff
Staff accounts can turn on two-step sign-in. With it on, a password alone is not enough to get in: a code from their authenticator app is needed too.
Technical detailTime based one-time passcodes (TOTP) from an authenticator app.
Encrypted while it travels
Information is encrypted while it travels between your browser and NameCRM.
Technical detailEncryption in transit over HTTPS (TLS).
AI that does not train on your data
NameCRM's AI features, including drafting, assistants, the AI phone receptionist and transcription, use Anthropic, Deepgram and ElevenLabs. We have set each of these providers so that the content we send them is not used to train their models.
Technical detailThe setting on each provider, and where each one runs, is listed on our AI trust page. See the AI trust page
Data residency
Where your data lives
Your records are stored in Canada. The servers that run the application are in the United States, and information passes through them on the way to the database. Our privacy policy says the same.
Database and file storage
Canada (Montreal)Supabase
Region ca-central-1
Application servers
United StatesVercel
Runs the application and its server functions
Retention
How long we keep things
Deleting something in NameCRM has a clear, written outcome.
You delete a record
It moves to Trash and is permanently deleted after 30 days.
An account closes
Its data is kept for 90 days so the account can be reopened with everything in place. After 90 days it is deleted.
Invoices and payment records
Kept for 6 years, as Canada Revenue Agency rules require.
The rules we follow
- BC's Personal Information Protection Act (PIPA) governs how we handle personal information in British Columbia
- Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) applies when information crosses a provincial or national border
- Commercial email and text messages sent through NameCRM follow Canada's Anti-Spam Legislation (CASL)
- Our privacy policy names a Privacy Officer, Seemab Akbar, who takes any question or request about your information
Written by the Nametech Canada team. Every statement on this page was checked on September 28, 2026.
