Skip to content
closerr
Trust & Security

How we protect your customer data.

Closerr is a mobile-first CRM trusted by field sales teams in the UK merchant services industry. This page lays out our security posture, what we do today, what we're working towards, and who you can talk to if you have questions.

UK GDPR aligned PCI DSS SAQ-A scope (no card data on Closerr infrastructure) TLS 1.2+ everywhere AES-256 at rest Cyber Essentials — submission in flight SOC 2 Type II — audit roadmapped

Security at a glance

Defence in depth, least-privilege access, and tenant data isolation are baked into the platform from the start.

Tenant isolation

Every database query is filtered by organisationId. Your data is never returned in a query for another customer.

Role-based access

Four roles per workspace — owner, admin, sales manager, sales rep — with enforced server-side authorisation on every action.

Encryption

AES-256 at rest and TLS 1.2+ in transit. HSTS enforced on every Closerr domain.

Authentication

SSO via Google Workspace, Microsoft Entra ID, and Apple. Email/password supported with bcrypt hashing.

Audit logging

Authentication, privileged actions, and webhook handling are logged. Logs retained for at least 90 days.

Backups

Continuous point-in-time recovery with 30-day retention. Restore tested quarterly.

Payments

All payment card data is handled by Stripe (PCI DSS Level 1). Closerr never stores or processes card numbers.

Patching

Critical vulnerabilities patched within 48 hours; high within 14 days. Dependencies scanned weekly.

Compliance & certifications

Where we are today, what's in flight, and what's on the roadmap. We don't claim certifications we don't have.

StandardStatusNotes
UK GDPR / Data Protection Act 2018LiveDPIA + ROPA register maintained. Data subject requests handled within 30 days.
PCI DSS — SAQ-A scopeLiveAll card data captured by Stripe Elements. No PAN on Closerr infrastructure.
Cyber Essentials (UK NCSC)Submission in flightTarget: certified within 60 days. Plus level targeted within 90 days of basic.
SOC 2 Type IIAudit roadmappedControls inventory in place today; full audit on the 12-month roadmap.
ISO 27001Under evaluationDecision after SOC 2 completion.
Independent penetration testScheduledFirst engagement scheduled within 90 days. Scope document available on request.

Sub-processors

The third-party services that process Closerr customer data on our behalf. Customers are notified at least 30 days in advance of any change to this list.

Sub-processorPurposeRegion
ReplitProduction hosting, managed PostgreSQL, object storageUS (underlying hyperscaler region per deployment)
StripeSubscription billing & payments (web)UK / EU / US
RevenueCatMobile in-app subscription managementUS
OpenAILLM inference (Closerr Assistant), voice transcriptionUS (no training on submitted data — enterprise terms applied)
ResendTransactional email deliveryUS
GoogleCalendar / Gmail integration (when customer connects), SSOGlobal
MicrosoftOutlook / Mail integration (when customer connects), SSO (Entra ID)Global (EU residency where elected)
AppleSign in with Apple (SSO)US

Data handling

Plain-language answers to the questions customers actually ask.

Do you train AI on our data?

No. OpenAI is bound by enterprise terms that prohibit training on data submitted via the API. We don't train any model on customer data.

Where is our data stored?

Replit-managed PostgreSQL with regional selection at provisioning. UK / EU residency available on request.

Can we export our data?

Yes. CSV / JSON export available for every object type via the API and the in-app back-office. You always retain ownership.

What happens if we leave?

You can export everything before cancellation. After deletion, your data is purged within 30 days from primary storage and within 90 days from backups.

Who can access our data internally?

Production administrative access is time-boxed, MFA-protected, and logged. Quarterly access reviews confirm only authorised staff have any access.

What if there's a breach?

Confirmed material incidents are notified to affected customers and (where applicable) the ICO within 72 hours of confirmation. A full post-incident report follows within 14 days.

For procurement & security teams

Documents we can share under NDA on request.

Changelog

Material changes to our security posture or sub-processor list.

May 2026Trust page published. Controls inventory + policy pack + SIG Lite / CAIQ pre-fills available on request.
May 2026Cyber Essentials self-assessment prepared for submission.
May 2026Independent penetration test scheduled. Scope document available.

Talk to us

The fastest way to get a security question answered or to request our compliance documents under NDA.

Generalhello@closerr.co.uk
Securitysecurity@closerr.co.uk
Data protectionprivacy@closerr.co.uk
Responsible disclosuresecurity@closerr.co.uk