Security and data privacy

How your data is kept separate

Who holds your data?

Kando CRM runs on a multi-tenant infrastructure: each organisation's data stays in its own space. Demo accounts are opened in separate branches of a shared CRM environment; access to customers, quotes and tasks is limited to the branch scope.

Permissions and data scope are enforced on the server; demo users can access only their own branch's records.

Security and permissions

Branch scope

Every demo account is opened in its own branch. Customer, quote, task and document records are queried only within that branch.

Two-factor authentication

2FA can be enabled per user; password reset and session security settings are managed from the user screen.

Role packages

Permissions are granted through ready-made role packages, not one by one. Administrator roles cannot be selected in demo accounts.

Change history

Changes to customer records are tracked in the history screen; you always know who updated a record and when.

KVKK consent records

Customer permissions and consent history are kept on a separate screen; you can report which permission was obtained and when.

Soft delete

Deleted records are not destroyed in the database; they are deactivated. A record deleted by mistake can be restored.