PearCRM security practices for infrastructure, encryption, access control, backups, monitoring, and responsible disclosure.
PearCRM is committed to protecting customer information through appropriate technical and organizational security measures.
Infrastructure
PearCRM uses reputable hosting providers and secure cloud infrastructure designed to support availability and reliability.
Encryption
- HTTPS/TLS encryption is used for data transmitted between users and the Service.
- Passwords are never stored in plain text and are securely hashed.
Access Control
Access to systems containing customer information is limited to authorized personnel when necessary for operating and maintaining the Service.
Monitoring
PearCRM may monitor system performance, errors, and security events to detect abuse, fraud, or unauthorized access.
Backups
Backups may be created periodically to support disaster recovery and business continuity.
Backups are retained only for as long as reasonably necessary.
Third-Party Integrations
Customers may connect third-party services such as Telegram, Discord, Stripe, WooCommerce, Meta, or other supported providers.
PearCRM is not responsible for the security practices of third-party services.
Customer Responsibilities
Customers are responsible for:
- using strong passwords;
- enabling multi-factor authentication where available;
- protecting account credentials;
- managing user permissions within their workspace;
- ensuring that data uploaded to PearCRM complies with applicable laws.
Security Incidents
If PearCRM becomes aware of a confirmed security incident affecting customer data, we will notify affected customers without undue delay where required by applicable law.
No Absolute Security
While PearCRM follows industry-standard security practices, no online service can guarantee complete protection against every cyberattack, vulnerability, or unauthorized access.