Security and data protection at Lavisho TT
Your CRM holds your customers, prices and people data. Here is exactly how we protect it — only controls that are actually in place are listed.
Last updated: 6 September 2026
Security Overview
Lavisho TT is a multi-tenant CRM built for field sales teams, and it holds customer records, pricing, and employee attendance data. This page lists the technical and organisational controls that are actually in place today, not a generic security checklist. Where a control is not yet available, we say so directly.
Our approach centres on encryption in transit and at rest, strict tenant isolation with row-level security, role-based access control, and audit logging, all backed by the security practices of our managed cloud infrastructure providers.
Data Encryption
Encryption in Transit — TLS
All traffic between your browser or mobile app and Lavisho TT is encrypted using TLS.
Encryption at Rest — managed cloud database and storage
Customer data, files, and selfies/attachments are stored using our managed cloud database and storage provider, which encrypts data at rest by default.
Identity & Access Management
Authentication
Users sign in with email and password. Accounts issued directly by an administrator require the user to change their password on first sign-in, and sessions are managed so admins can review and revoke access.
MFA
Multi-factor authentication is not yet available in Lavisho TT; it is on our roadmap.
SSO
Optional single sign-on (SSO) is available for Enterprise workspaces.
Role-Based Access Control
Access is governed by roles (admin, manager, employee) combined with granular permission profiles and field-level visibility, so a company can restrict who sees pricing, contacts or financial detail. Users can be deactivated instantly, immediately revoking access.
Multi-Tenant Architecture
Tenant Isolation
Lavisho TT is multi-tenant: every table is protected by row-level security so one company can never read another company's records, even inside a multi-company group. Access is additionally checked with server-side authorisation on every action, and company-scoped policies enforce which workspace a request is allowed to touch.
Audit Logs
Sign-ins, record changes, approvals and quotation actions are written to audit logs that admins can review and export, giving visibility into who did what and when.
Backup & Recovery
Our managed cloud database provider performs automated database backups as part of its infrastructure.
Business Continuity
Lavisho TT is served from a globally distributed edge network, and our managed database provider operates the underlying backup infrastructure. We do not currently publish specific recovery point or recovery time targets.
Data Retention
Customer data is retained while a workspace is active, and for 30 days after termination to allow export. Audit logs and backups may be retained by our infrastructure providers for a period beyond this for security purposes.
Data Deletion
Workspace admins can export their data at any time and request deletion. Deletion requests are processed as an export followed by a purge, and complete within 30 days unless the law requires us to retain certain records for longer.
Incident Response
Security issues can be reported to our support team. We investigate reported incidents, take steps to contain them, and notify affected customers of material incidents.
Vulnerability Management
We run regular automated security scans of our codebase and database policies, and use dependency scanning to catch known vulnerabilities in third-party packages we rely on.
Penetration Testing
We have not yet commissioned an independent third-party penetration test. Enterprise customers may request one under NDA as part of procurement.
Subprocessors
Lavisho TT relies on a small number of infrastructure providers to run the Service, categorised generically below rather than by name in this public page:
- A managed cloud database, authentication and storage provider, hosted on SOC 2-audited infrastructure.
- An edge hosting and content-delivery network (CDN) provider.
- A transactional email provider, used to deliver account and notification emails.
- AI model providers, used only to power optional AI features when a customer initiates a request that uses them.
A named list of current subprocessors is available on request as part of our Data Processing Addendum.
Infrastructure
Hosted on SOC 2-audited cloud infrastructure with encryption in transit and at rest.
To be clear, Lavisho TT itself does not hold a SOC 2 or ISO 27001 certification and we do not claim to; the statement above refers to the audited status of the underlying cloud infrastructure providers we use.
Security Contact
Report a security issue or ask a question by emailing support@lavishott.cloud with "Security" in the subject line.
Responsible Disclosure
We welcome good-faith reports of security issues. If you report a vulnerability responsibly, we ask for reasonable time to investigate and fix it before any public disclosure, and we will not pursue legal action against researchers acting in good faith. We do not currently operate a paid bug bounty program.
Compliance & Privacy
Our processing terms are described in the Data Processing Addendum and Privacy Policy.
Privacy for field staff
Location is captured at check-in, check-out and visit events that the employee initiates — not as continuous background surveillance. Companies control which roles can view maps and selfies.
Last updated: 6 September 2026
Talk to us about your team
Tell us about your team size, industry and current tools and we will map out a rollout with you.