CGCRM GOALIE
CRM Goalie ← Back to site
Trust

How we protect your data

Plain statement of what we do · September 2026

CRM Goalie holds two kinds of sensitive information: the key that lets us read and write your CRM, and the lead records we judge on your behalf. Here is exactly how each is handled. No marketing language; if something below changes, this page changes first.

Credentials

Encrypted at rest, decrypted only in the engine

Your CRM key is encrypted with AES-256-GCM the moment you paste it. It is decrypted in memory only when the engine talks to your CRM, and never shown again in the dashboard, logs, or emails.

Isolation

One client can never read another's records

Every row in the database carries your workspace ID and is protected by row-level security enforced by the database itself, not just by our application code.

Transport

Encrypted in transit, everywhere

All traffic between your browser, our servers, your CRM, and our providers uses TLS. Intake URLs carry a per-client secret token; the lead mailbox address is unguessable.

Fail open

Our downtime never loses your lead

If any part of CRM Goalie is unavailable, leads pass through to your CRM unchecked and are logged for review. Worst case is one junk lead through, never one real lead lost.

Nothing deleted

Every verdict is reversible

Rejected leads are parked with their evidence and restored with one click. The ledger is append-only; we do not edit or delete decision history.

Delivery receipts

We prove the lead landed

After every delivery we read the record back from your CRM and keep a receipt. A lead that fails that check raises an alert to our team within seconds.

Access

Least privilege, named people

Production access is limited to the people who operate the service. Sign-in to your dashboard is by single-use magic link; there are no passwords to leak.

Providers

A short, named list of subprocessors

Vercel (hosting), Supabase (database and authentication), Stripe (billing), Resend (email), a phone-lookup provider (Telnyx, IPQualityScore, or Twilio), and Anthropic for optional message screening (message text only, no contact details).

01Retention

Lead records and the decision ledger stay for the life of your account, because the ledger is your permanent record. After cancellation your data remains exportable for 90 days, then is deleted. CRM credentials are deleted the moment a connection is removed.

02Incidents

If we learn of a breach affecting your data, we notify you without undue delay with what happened, what was affected, and what we did. Engine incidents that could affect lead flow are fixed the same day and reported in your weekly digest.

03Roadmap

Independent SOC 2 assessment is planned once client volume justifies the audit. Until then, this page is the commitment and the Privacy Policy and Terms are the contract.

Questions about security, or a vulnerability to report: security@crmgoalie.com. We answer within one business day.