Platform – Security
Security built into every layer.
From granular per-module permissions to two-factor authentication, SSO, data isolation and GDPR tools – EasyCRM protects your data and your team without compromise.
Access control
Granular permissions for every module
EasyCRM uses Spatie RBAC with team scoping. Each role has precisely defined permissions for every module – contacts, leads, pipeline, inbox, telephony, reports, billing and privacy. The organisation admin creates and edits roles directly in settings without any code change. Permissions are enforced on every HTTP request, so no team member can access data they are not entitled to.
- Granular permissions per module (contacts, leads, pipeline, inbox, telephony, reports, billing)
- Team scoping – each member sees only what belongs to them
- Roles: admin, manager, salesperson, support – fully configurable
- Role management directly in settings
- Permissions enforced on every request
Authentication
Two-factor authentication and enterprise SSO
EasyCRM supports TOTP (time-based one-time passwords) via any authenticator app – Google Authenticator, Authy or 1Password. Recovery codes ensure access even if a device is lost. An admin can enforce 2FA for the entire organisation with a single toggle. For enterprise teams with an existing identity provider, SSO is available via SAML 2.0 (SP-initiated, ACS callback, metadata endpoint, JIT provisioning) or OIDC with PKCE and nonce and JWKS signature verification – compatible with Google Workspace, Azure AD and Okta. SSO is available on the Pro plan.
- 2FA via authenticator app (TOTP)
- Recovery codes for regaining access
- Organisation can enforce 2FA for all members
- SSO via SAML 2.0 (Pro) – JIT provisioning
- SSO via OIDC + PKCE (Pro) – compatible with Google Workspace, Azure AD, Okta
Isolation & GDPR
GDPR and per-org data isolation
Every organisation has its own subdomain and all database queries are automatically scoped to `organization_id` – one customer will never see another's data. EasyCRM ships with GDPR tools built in: record consent per contact with a full change history, export all contact data as JSON at any time, or anonymise PII records on request. The audit log records every change in the system. ULID identifiers ensure numeric IDs never leak into URLs or the API. Webhooks (Meta, email, API) are verified by HMAC signature before processing.
- Every organisation has an isolated, scoped database
- GDPR: consent history, JSON data export, PII anonymisation
- Audit log of every action
- ULID identifiers – no numeric IDs in URLs or API
- HMAC webhook verification (Meta, email, API)
What you get
Security that scales with your team
- Every team member has exactly the access they need
- 2FA protects every account even without an enterprise IdP
- SSO integrates EasyCRM into your corporate identity (Pro)
- Every organisation sees only its own data
- GDPR tools available from day one
- Customer consent recorded with a full change history
- Audit log captures every change in the system
Related topics
Frequently asked questions
Questions about EasyCRM security
Give your team the right access from day one
Register for free and configure roles, 2FA and GDPR tools right after sign-up.