Snapshot 70662
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Security & Trust What a security or procurement reviewer needs to evaluate CRMJetty: how portal access is controlled, where portal data sits, and what we do not claim yet. Every item on this page is either verifiable by you or backed by something we can send you. The gaps are listed too. Independently Reviewed Three things on this page were checked by someone other than us. They're listed on their own because the rest of the page is our own account of our own product. Salesforce · AppExchange Salesforce AppExchange Security Review Our Salesforce products are listed on the Salesforce AppExchange, which requires passing Salesforce's mandatory security review. Salesforce's mandatory security review WordPress Customer Portal listed since 2017 Listing is public and verifiable Checked by Salesforce View the AppExchange Listing Dynamics 365 · Microsoft AppSource Microsoft AppSource Certification Customer Portal for Dynamics 365 is published on Microsoft AppSource, which requires passing Microsoft's technical certification. Microsoft's technical certification Published under our parent company's publisher account, BizTech IT Consulting Listing is public and verifiable Checked by Microsoft View the AppSource Listing Parent Company · ISO ISO 27001 and ISO 9001 Certificates Biztech IT Consultancy Private Limited holds ISO 27001 for information security and ISO 9001 for quality management. Held by Biztech IT Consultancy Private Limited, not by the CRMJetty brand Certified scope is not published here Certificates and scope statement sent under NDA Certificates held by our parent company Access Control and Authentication Who can reach which record is configuration, not a support ticket. Record-Level Data Scoping Portal users are scoped by their CRM identity, not just by role: contact-based, so a user sees only their own records, or account-based, so they see their organization's. Configured per module. Role-Based Access Control Granular module permissions are set per role. A portal user sees the records their role allows and nothing else. Role permissions sit alongside the record-level scoping above, not instead of it. Portal User Groups Create, edit, delete and subpanel access, configured per group and per module. Groups let you apply one permission set to many portal users rather than configuring each account individually. Two-Factor Authentication OTP-based two-factor authentication, with each one-time code valid for 30 minutes. It adds a second factor beyond the password at portal sign-in. OAuth 2.0 Salesforce connections run through a Salesforce Connected App using OAuth 2.0. The requested scope is "Access and manage your data (api)" — a full-data API scope, not a narrow one. Single Sign-On Microsoft Identity for enterprise sign-in, plus Google and Facebook social login for consumer-facing portals. There is no SAML integration today and no Okta connector — raise that now if your review requires one. reCAPTCHA v2.0 reCAPTCHA v2.0 on the login, signup and forgot-password flows, so automated credential-stuffing attempts hit a challenge before they reach the authentication step. IP Restriction Portal access can be limited to your own IP ranges, so a portal intended for staff or a named client is not reachable from the open internet. Sub-Admin Accounts Scoped admin permissions, so routine portal administration does not need a full-access account. Day-to-day tasks can be delegated without handing over the keys to the whole portal. User Approval and Email Verification New portal users can be held for approval before their account becomes active, and email verification confirms the address belongs to the person registering. Activity Visibility The portal surfaces a recent-activity view for portal users and admins. We do not publish a formal audit-log specification covering event coverage, immutability or retention — ask what your deployment records. Where Your Data Lives Including the part we're still writing down. Your CRM Stays the System of Record Portal data is fetched on demand from your CRM over secure APIs rather than replicated into a second database, so the CRM you already audit stays the system of record. What the Portal Stores Outside Your CRM What lives portal-side is the portal's own layer: user accounts and credentials, session and OTP data, configuration and layouts, plus the WordPress database on those products. No field-level inventory is published yet — ask for yours. Encrypted in Transit Portal traffic runs over HTTPS/TLS, and an SSL certificate is mandatory on every deployment, cloud or on-premise. It is not optional and not a paid extra, so no portal goes live without one. Encryption at Rest This depends on where the portal runs. On your own server or Azure subscription it is yours to configure and verify; for our cloud, ask about your instance. We publish no blanket at-rest claim. Deploy It Where Your Policy Requires Our cloud, on-premise on your own server, or your own Azure subscription. On-premise is the cleanest answer to a data-location requirement, because the hosting decision stays with you. How a Deployment Runs → Third-Party Services in the Portal Optional integrations put portal data in front of third parties: Stripe and PayPal, SharePoint, Tawk.to, Google Translate, Google Analytics and Zoho SalesIQ. Which are active is your choice; no subprocessor list is published yet. Getting Your Data Out, and Deleting It CSV export and import are built in, along with bulk record deletion. Your CRM records are unaffected either way, because they were never moved out of the CRM. Sync Is Asynchronous The portal and your CRM are not always instantaneously in step. Sync timing depends on your CRM's API limits, and we would rather you knew that now than discovered it in UAT. Products Have Different Architectures The no-code platform is at v6.0. The WordPress portals are separate standalone products: Salesforce Customer Portal for WordPress v5.5.0 and SuiteCRM WordPress Customer Portal v4.3.0. Review them separately and pin the version you assessed. What We Do Not Claim Yet A trust page is only worth reading if the gaps are on it. As of August 2026, none of the following is available to send you. If one of them is a hard requirement for your review, raise it now rather than at contract stage. SOC 2 There's no SOC 2 Type I or Type II report. Third-Party Penetration Test We have no current third-party penetration test summary to share. Uptime SLA No published availability percentage. Our support response commitments are a different thing and shouldn't be read as an uptime guarantee. Support Policy → Data Processing Agreement No standard DPA or Standard Contractual Clauses template is available for signature yet. Data Retention and Deletion Policy Not published. The export and deletion tools above are product features, not a retention policy. GDPR and CCPA Statements We haven't published a GDPR or CCPA compliance statement, and we're not claiming one here. Incident Response and Breach Notification No published incident response plan or breach notification window. Accessibility Conformance No VPAT or WCAG conformance report. Formal Vulnerability Disclosure There's no dedicated security mailbox yet. Security reports come in through the support ticket queue and are triaged there. Questions Reviewers Ask Where is my customers' data stored? Your CRM stays the system of record, and portal data is fetched on demand over secure APIs rather than replicated. What lives portal-side is the portal's own layer: user accounts and credentials, session and OTP data, portal configuration and layouts, and for the WordPress products the WordPress database itself. We haven't yet published a field-level inventory per product and deployment type, so ask us and we'll write it out for your specific build. Is CRMJetty GDPR compliant? We haven't published a GDPR compliance statement and we're not claiming one. CRMJetty is operated by Biztech IT Consultancy Private Limited in India, so a transfer out of the EEA is in scope for your assessment. If GDPR documentation is a requirement for your purchase, raise it before evaluation rather than at contract stage. Do you have SOC 2? No. There's no SOC 2 Type I or Type II report. Are you ISO 27001 certified? The certificates are held by our parent company, Biztech IT Consultancy Private Limited, not by the CRMJetty brand. ISO 27001 covers information security and ISO 9001 covers quality management. We haven't published the certified scope. Ask us and we'll send the certificates including the scope statement under NDA. Can we run it on-premise? Yes. Our cloud, on-premise on your own server, or your own Azure subscription. If your requirement is that data stays in a particular country, on-premise answers it directly, because the hosting decision stays with you. Which identity providers do you support for single sign-on? Microsoft Identity for enterprise sign-in, and Google and Facebook social login for consumer-facing portals. Salesforce portals also authenticate through OAuth 2.0 via a Salesforce Connected App. We don't support SAML today. If your identity provider isn't on that list, confirm compatibility before you buy. Can one portal user see another customer's records? No, provided access is configured. Portal users are scoped by their CRM identity, either contact-based so a user sees only their own records, or account-based so a user sees their organization's records. That scoping is set per module, so confirm it during configuration for every module you switch on. How do you handle a security incident? We don't have a published incident response and breach notification policy. If that's a requirement for your review, ask us for the current process in writing before contracting. Who do we sign the contract with? Biztech IT Consultancy Private Limited. CRMJetty is a registered domain of that company, and it's named as the data controller and contracting party in our privacy policy. Need Something That Isn't on This Page? Security questionnaires, certificate details and architecture questions all go to the same place. Tell us what your review needs and we'll answer in writing. Contact Us