Security & Privacy
How we protect the data that flows through AllyOneCRM and AllyOneMail. This page covers principles and practices — for technical implementation details under NDA, talk to our team.
🔐 Encryption
All communication with the API runs over TLS. Integration credentials (ad tokens, SMTP, WhatsApp Business) are encrypted at rest. API keys are stored only as a hash — never in plain text.
🏢 Tenant isolation
Each account operates in logical isolation reinforced at the database level (Row Level Security), not just at the application layer.
🔑 Two-factor authentication
Available on all accounts, based on standard TOTP (compatible with Google Authenticator, Authy and similar), with recovery codes.
📋 LGPD
On-demand personal data export and deletion tools (LGPD is Brazil's data-protection law, equivalent to GDPR), per-channel consent records and retention policies configurable per account.
🛡️ Rate limits
Every public API is protected by rate limiting — see the real limits in Authentication.
🔍 Continuous auditing
Recurring security review of code and infrastructure, as part of the normal development process — not a one-off event.
Responsible disclosure
Found a vulnerability? We want to know before anyone else. Report it to caio.santos@allyonecorp.com — we respond to every good-faith report.
Where your data lives
Production infrastructure is in the European Union. For data subjects in Brazil, the international transfer is based on an adequacy decision (LGPD, art. 33, I): through ANPD Resolution No. 32/2026, Brazil's data protection authority recognized the European Union and the European Economic Area as providing an adequate level of protection, with no additional contractual clauses required. Customers who need data stored in Brazil can request a dedicated environment.
