Trust & compliance

Practical security for a multi-tenant CRM.No overstated certifications.

DeskGuru Technologies, based in Toronto, Ontario, protects customer data with encryption, organization isolation, optional MFA, and production-only access controls. We do not claim SOC 2, HIPAA, or SSO until those programs are in place.

Encryption

Data protected in transit and at rest

Traffic to DeskGuru uses TLS. Customer data is stored in Postgres with encryption at rest. Access is scoped to your organization through authentication and row-level security.

Tenant isolation

Your workspace stays yours

Each customer organization is isolated in the database. Team roles and permissions control who can see contacts, jobs, invoices, and settings inside your account.

Privacy

Clear ownership of your data

You own the business data you put in DeskGuru. You can update account details in Settings, delete your account, or email us for access and deletion requests.

Account security

Optional multi-factor authentication

Users can enable TOTP or SMS multi-factor authentication from Settings. We recommend turning it on for owners and anyone with billing or admin access.

Defense in depth

How we secure the platform

Infrastructure security

  • Hosted on the Vercel global edge network
  • Encryption: TLS 1.2+ in transit and AES-256 at rest
  • DDoS mitigation & Web Application Firewall (WAF)

Product security

  • Optional multi-factor authentication (TOTP or SMS)
  • Role-based permissions inside each organization
  • Organization-scoped data access via row-level security

Operational security

  • Production access limited to operators who need it
  • Secrets stored as environment variables, not in the client
  • Support requests handled at info@deskguru.app

Application security

  • Report a security issue to info@deskguru.app
  • Debug and diagnostic routes blocked in production
  • Webhook signatures verified for Twilio inbound SMS