Trust & Security
Security at QikCRM
Your customer data is the heart of your business, so we treat it that way. Here is a plain-English summary of how QikCRM stores, protects, and handles the information you trust us with.
Last updated: September 2026
1. Where Your Data Lives
QikCRM is hosted on managed cloud infrastructure inside the European Union. Your CRM records, files, and account details stay within EU data centres, which keeps you on the right side of data residency expectations for Irish and UK businesses.
We do not sell your data, and we do not use the contents of your CRM to advertise to you or anyone else.
2. Encryption
All traffic between your browser and QikCRM is encrypted in transit using TLS. If you ever see a page load over plain HTTP, that is a bug we want to hear about.
Data stored in our database and file storage is encrypted at rest by the underlying cloud platform. Passwords are never stored in plain text, they are hashed using a modern, salted algorithm.
3. Access Controls
Every person who logs in has their own named account. QikCRM supports role-based access, so owners and managers can decide who sees and changes what.
We protect sign-in with rate limiting and account lockout after repeated failed attempts, which blunts brute-force and credential-stuffing attacks. Password reset links and email verification tokens are single-use and time-limited.
On our side, access to production systems is limited to the people who need it to run the service, and that access is kept to a minimum.
4. Account Isolation
QikCRM is multi-tenant, which is the normal model for cloud software. Each organisation's data is scoped to that organisation, and every request is checked against the logged-in user's account before any record is returned.
In plain terms, one business cannot see another business's contacts, deals, or documents.
5. Backups & Recovery
The database is backed up regularly by the managed platform, with point-in-time recovery available to help us restore service after a serious failure.
Backups are not a substitute for your own good habits. If you need to keep a copy of your records outside QikCRM, our export features let you take your data with you at any time.
6. Sub-Processors
We rely on a small set of trusted providers to run QikCRM. The main ones are:
- Cloud hosting and database for running the application and storing your data within the EU.
- AI providers (for example Mistral, Microsoft Azure OpenAI, or OpenAI) that power the AI features. Prompts are sent to generate a result and your CRM data is not used to train their models.
- Integration connectors that let you link tools like Gmail, Outlook, Slack, and HubSpot. These only move the data you explicitly authorise.
- Email delivery for transactional messages such as verification, password resets, and notifications.
For a full, current list of sub-processors, or to ask a specific question, email [email protected].
7. Data Protection & GDPR
For the data you put into QikCRM about your own customers, you are the data controller and QikCRM acts as your data processor. We process that data on your instructions to provide the service.
We support the usual data subject rights, including access, correction, and deletion. Our privacy policy explains what we collect and why, and our AI policy covers how AI features handle your data.
8. Responsible Disclosure
If you believe you have found a security issue in QikCRM, please tell us before sharing it publicly. Email [email protected] with the details and steps to reproduce it.
We take reports seriously, we will acknowledge yours, and we will not pursue action against researchers who act in good faith and avoid privacy violations or service disruption.
Have a security or compliance question? Get in touch.