Security

Security and data protection at Lavisho TT

Your CRM holds your customers, prices and people data. Here is exactly how we protect it — only controls that are actually in place are listed.

Start free trial

Last updated: 6 September 2026

Security Overview

Lavisho TT is a multi-tenant CRM built for field sales teams, and it holds customer records, pricing, and employee attendance data. This page lists the technical and organisational controls that are actually in place today, not a generic security checklist. Where a control is not yet available, we say so directly.

Our approach centres on encryption in transit and at rest, strict tenant isolation with row-level security, role-based access control, and audit logging, all backed by the security practices of our managed cloud infrastructure providers.

Data Encryption

Encryption in Transit — TLS

All traffic between your browser or mobile app and Lavisho TT is encrypted using TLS.

Encryption at Rest — managed cloud database and storage

Customer data, files, and selfies/attachments are stored using our managed cloud database and storage provider, which encrypts data at rest by default.

Identity & Access Management

Authentication

Users sign in with email and password. Accounts issued directly by an administrator require the user to change their password on first sign-in, and sessions are managed so admins can review and revoke access.

MFA

Multi-factor authentication is not yet available in Lavisho TT; it is on our roadmap.

SSO

Optional single sign-on (SSO) is available for Enterprise workspaces.

Role-Based Access Control

Access is governed by roles (admin, manager, employee) combined with granular permission profiles and field-level visibility, so a company can restrict who sees pricing, contacts or financial detail. Users can be deactivated instantly, immediately revoking access.

Multi-Tenant Architecture

Tenant Isolation

Lavisho TT is multi-tenant: every table is protected by row-level security so one company can never read another company's records, even inside a multi-company group. Access is additionally checked with server-side authorisation on every action, and company-scoped policies enforce which workspace a request is allowed to touch.

Audit Logs

Sign-ins, record changes, approvals and quotation actions are written to audit logs that admins can review and export, giving visibility into who did what and when.

Backup & Recovery

Our managed cloud database provider performs automated database backups as part of its infrastructure.

Business Continuity

Lavisho TT is served from a globally distributed edge network, and our managed database provider operates the underlying backup infrastructure. We do not currently publish specific recovery point or recovery time targets.

Data Retention

Customer data is retained while a workspace is active, and for 30 days after termination to allow export. Audit logs and backups may be retained by our infrastructure providers for a period beyond this for security purposes.

Data Deletion

Workspace admins can export their data at any time and request deletion. Deletion requests are processed as an export followed by a purge, and complete within 30 days unless the law requires us to retain certain records for longer.

Incident Response

Security issues can be reported to our support team. We investigate reported incidents, take steps to contain them, and notify affected customers of material incidents.

Vulnerability Management

We run regular automated security scans of our codebase and database policies, and use dependency scanning to catch known vulnerabilities in third-party packages we rely on.

Penetration Testing

We have not yet commissioned an independent third-party penetration test. Enterprise customers may request one under NDA as part of procurement.

Subprocessors

Lavisho TT relies on a small number of infrastructure providers to run the Service, categorised generically below rather than by name in this public page:

  • A managed cloud database, authentication and storage provider, hosted on SOC 2-audited infrastructure.
  • An edge hosting and content-delivery network (CDN) provider.
  • A transactional email provider, used to deliver account and notification emails.
  • AI model providers, used only to power optional AI features when a customer initiates a request that uses them.

A named list of current subprocessors is available on request as part of our Data Processing Addendum.

Infrastructure

Hosted on SOC 2-audited cloud infrastructure with encryption in transit and at rest.

To be clear, Lavisho TT itself does not hold a SOC 2 or ISO 27001 certification and we do not claim to; the statement above refers to the audited status of the underlying cloud infrastructure providers we use.

Security Contact

Report a security issue or ask a question by emailing support@lavishott.cloud with "Security" in the subject line.

Responsible Disclosure

We welcome good-faith reports of security issues. If you report a vulnerability responsibly, we ask for reasonable time to investigate and fix it before any public disclosure, and we will not pursue legal action against researchers acting in good faith. We do not currently operate a paid bug bounty program.

Compliance & Privacy

Our processing terms are described in the Data Processing Addendum and Privacy Policy.

Privacy for field staff

Location is captured at check-in, check-out and visit events that the employee initiates — not as continuous background surveillance. Companies control which roles can view maps and selfies.

Last updated: 6 September 2026

Talk to us about your team

Tell us about your team size, industry and current tools and we will map out a rollout with you.