Third Party Index

Snapshot 70662

Document
Trust center
URL
https://www.crmjetty.com/security/
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
119888 bytes
SHA-256 (raw)
86620007bfa3308420be0c53031f9cee7f823476a3741d95961d0f22a65babbe
SHA-256 (normalized text)
170280b30a693df30d55fbb185bedaf2d2a2bbb11eacf8061d386e9c2e881249

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Security & Trust
What a security or procurement reviewer needs to evaluate CRMJetty: how portal access is controlled, where portal data sits, and what we do not claim yet.
Every item on this page is either verifiable by you or backed by something we can send you. The gaps are listed too.
Independently Reviewed
Three things on this page were checked by someone other than us. They're listed on their own because the rest of the page is our own account of our own product.
Salesforce · AppExchange
Salesforce AppExchange Security Review
Our Salesforce products are listed on the Salesforce AppExchange, which requires passing Salesforce's mandatory security review.
Salesforce's mandatory security review
WordPress Customer Portal listed since 2017
Listing is public and verifiable
Checked by Salesforce View the AppExchange Listing
Dynamics 365 · Microsoft AppSource
Microsoft AppSource Certification
Customer Portal for Dynamics 365 is published on Microsoft AppSource, which requires passing Microsoft's technical certification.
Microsoft's technical certification
Published under our parent company's publisher account, BizTech IT Consulting
Listing is public and verifiable
Checked by Microsoft View the AppSource Listing
Parent Company · ISO
ISO 27001 and ISO 9001 Certificates
Biztech IT Consultancy Private Limited holds ISO 27001 for information security and ISO 9001 for quality management.
Held by Biztech IT Consultancy Private Limited, not by the CRMJetty brand
Certified scope is not published here
Certificates and scope statement sent under NDA
Certificates held by our parent company
Access Control and Authentication
Who can reach which record is configuration, not a support ticket.
Record-Level Data Scoping
Portal users are scoped by their CRM identity, not just by role: contact-based, so a user sees only their own records, or account-based, so they see their organization's. Configured per module.
Role-Based Access Control
Granular module permissions are set per role. A portal user sees the records their role allows and nothing else. Role permissions sit alongside the record-level scoping above, not instead of it.
Portal User Groups
Create, edit, delete and subpanel access, configured per group and per module. Groups let you apply one permission set to many portal users rather than configuring each account individually.
Two-Factor Authentication
OTP-based two-factor authentication, with each one-time code valid for 30 minutes. It adds a second factor beyond the password at portal sign-in.
OAuth 2.0
Salesforce connections run through a Salesforce Connected App using OAuth 2.0. The requested scope is "Access and manage your data (api)" — a full-data API scope, not a narrow one.
Single Sign-On
Microsoft Identity for enterprise sign-in, plus Google and Facebook social login for consumer-facing portals. There is no SAML integration today and no Okta connector — raise that now if your review requires one.
reCAPTCHA v2.0
reCAPTCHA v2.0 on the login, signup and forgot-password flows, so automated credential-stuffing attempts hit a challenge before they reach the authentication step.
IP Restriction
Portal access can be limited to your own IP ranges, so a portal intended for staff or a named client is not reachable from the open internet.
Sub-Admin Accounts
Scoped admin permissions, so routine portal administration does not need a full-access account. Day-to-day tasks can be delegated without handing over the keys to the whole portal.
User Approval and Email Verification
New portal users can be held for approval before their account becomes active, and email verification confirms the address belongs to the person registering.
Activity Visibility
The portal surfaces a recent-activity view for portal users and admins. We do not publish a formal audit-log specification covering event coverage, immutability or retention — ask what your deployment records.
Where Your Data Lives
Including the part we're still writing down.
Your CRM Stays the System of Record
Portal data is fetched on demand from your CRM over secure APIs rather than replicated into a second database, so the CRM you already audit stays the system of record.
What the Portal Stores Outside Your CRM
What lives portal-side is the portal's own layer: user accounts and credentials, session and OTP data, configuration and layouts, plus the WordPress database on those products. No field-level inventory is published yet — ask for yours.
Encrypted in Transit
Portal traffic runs over HTTPS/TLS, and an SSL certificate is mandatory on every deployment, cloud or on-premise. It is not optional and not a paid extra, so no portal goes live without one.
Encryption at Rest
This depends on where the portal runs. On your own server or Azure subscription it is yours to configure and verify; for our cloud, ask about your instance. We publish no blanket at-rest claim.
Deploy It Where Your Policy Requires
Our cloud, on-premise on your own server, or your own Azure subscription. On-premise is the cleanest answer to a data-location requirement, because the hosting decision stays with you.
How a Deployment Runs →
Third-Party Services in the Portal
Optional integrations put portal data in front of third parties: Stripe and PayPal, SharePoint, Tawk.to, Google Translate, Google Analytics and Zoho SalesIQ. Which are active is your choice; no subprocessor list is published yet.
Getting Your Data Out, and Deleting It
CSV export and import are built in, along with bulk record deletion. Your CRM records are unaffected either way, because they were never moved out of the CRM.
Sync Is Asynchronous
The portal and your CRM are not always instantaneously in step. Sync timing depends on your CRM's API limits, and we would rather you knew that now than discovered it in UAT.
Products Have Different Architectures
The no-code platform is at v6.0. The WordPress portals are separate standalone products: Salesforce Customer Portal for WordPress v5.5.0 and SuiteCRM WordPress Customer Portal v4.3.0. Review them separately and pin the version you assessed.
What We Do Not Claim Yet
A trust page is only worth reading if the gaps are on it. As of August 2026, none of the following is available to send you. If one of them is a hard requirement for your review, raise it now rather than at contract stage.
SOC 2
There's no SOC 2 Type I or Type II report.
Third-Party Penetration Test
We have no current third-party penetration test summary to share.
Uptime SLA
No published availability percentage. Our support response commitments are a different thing and shouldn't be read as an uptime guarantee.
Support Policy →
Data Processing Agreement
No standard DPA or Standard Contractual Clauses template is available for signature yet.
Data Retention and Deletion Policy
Not published. The export and deletion tools above are product features, not a retention policy.
GDPR and CCPA Statements
We haven't published a GDPR or CCPA compliance statement, and we're not claiming one here.
Incident Response and Breach Notification
No published incident response plan or breach notification window.
Accessibility Conformance
No VPAT or WCAG conformance report.
Formal Vulnerability Disclosure
There's no dedicated security mailbox yet. Security reports come in through the support ticket queue and are triaged there.
Questions Reviewers Ask
Where is my customers' data stored?
Your CRM stays the system of record, and portal data is fetched on demand over secure APIs rather than replicated. What lives portal-side is the portal's own layer: user accounts and credentials, session and OTP data, portal configuration and layouts, and for the WordPress products the WordPress database itself. We haven't yet published a field-level inventory per product and deployment type, so ask us and we'll write it out for your specific build.
Is CRMJetty GDPR compliant?
We haven't published a GDPR compliance statement and we're not claiming one. CRMJetty is operated by Biztech IT Consultancy Private Limited in India, so a transfer out of the EEA is in scope for your assessment. If GDPR documentation is a requirement for your purchase, raise it before evaluation rather than at contract stage.
Do you have SOC 2?
No. There's no SOC 2 Type I or Type II report.
Are you ISO 27001 certified?
The certificates are held by our parent company, Biztech IT Consultancy Private Limited, not by the CRMJetty brand. ISO 27001 covers information security and ISO 9001 covers quality management. We haven't published the certified scope. Ask us and we'll send the certificates including the scope statement under NDA.
Can we run it on-premise?
Yes. Our cloud, on-premise on your own server, or your own Azure subscription. If your requirement is that data stays in a particular country, on-premise answers it directly, because the hosting decision stays with you.
Which identity providers do you support for single sign-on?
Microsoft Identity for enterprise sign-in, and Google and Facebook social login for consumer-facing portals. Salesforce portals also authenticate through OAuth 2.0 via a Salesforce Connected App. We don't support SAML today. If your identity provider isn't on that list, confirm compatibility before you buy.
Can one portal user see another customer's records?
No, provided access is configured. Portal users are scoped by their CRM identity, either contact-based so a user sees only their own records, or account-based so a user sees their organization's records. That scoping is set per module, so confirm it during configuration for every module you switch on.
How do you handle a security incident?
We don't have a published incident response and breach notification policy. If that's a requirement for your review, ask us for the current process in writing before contracting.
Who do we sign the contract with?
Biztech IT Consultancy Private Limited. CRMJetty is a registered domain of that company, and it's named as the data controller and contracting party in our privacy policy.
Need Something That Isn't on This Page?
Security questionnaires, certificate details and architecture questions all go to the same place. Tell us what your review needs and we'll answer in writing.
Contact Us