Security

Your support inbox holds your most sensitive customer data.

Identity documents, payment disputes, account recovery: it all passes through support first. This page says exactly how that data is handled, including the parts most vendors leave vague.

  • AES-256-GCM at rest
  • TLS in transit
  • bcrypt cost 12
  • TOTP 2FA
  • Per-tenant isolation

Protection

Three layers, none of them optional.

In transit

Every connection runs over TLS: browser to app, app to your mailbox, app to any provider. Nothing about your support data crosses a network in the clear.

At rest

Mailbox OAuth tokens and two-factor seeds are sealed with AES-256-GCM before they reach the database. Passwords are bcrypt-hashed at cost 12 and never stored in a form anyone can reverse, us included.

In the application

Every query is scoped to a single workspace, so one tenant’s data is unreachable from another’s session. Rate limiting sits on all routes and tightens on sign-in.

Access

Who can do what, decided by you.

Support teams are not flat. The people who can read a KYC document are rarely the people who should be able to export the customer list.

A permission matrix, not fixed tiers
8 roles across 7 actions (view, edit, assign, escalate, close, export and manage), edited as a grid per workspace. A Finance specialist can see the tickets they need without being able to export your customer base.
The owner role cannot be edited away
Workspace Admin permissions are fixed at the full set, so a misconfigured matrix can never lock every administrator out of the workspace.
Two-factor authentication
Time-based codes from any authenticator app. An admin can require it workspace-wide, and staff without it are prompted until they enrol.
Sessions you can end
Idle sign-out after 30 minutes by default, with a 60-second warning first. Active sessions are listed per user and can be revoked individually. Useful the day a laptop goes missing.
Password rules you set
A minimum length of 10 characters by default, raised as high as your policy requires.

Accountability

Nothing happens without a record.

Every change is written to an audit log with who did it, what changed, and when, ticket edits, assignments, logins, exports and uploads. Managers can filter it, and it is there for your auditors without anyone having to reconstruct a story afterwards.

Sign-ins, permission changes and any view of a customer’s contact details are kept for 365 days and cannot be shortened, even by an administrator. Ordinary activity follows a retention window your workspace sets, and high-volume automated entries a shorter one, so the trail that matters survives while the machine chatter does not.

It records the decisions the system makes on its own, too. When triage judges an incoming email not to be a support request, that message stays in your inbox and the reason is logged, so “why didn’t this become a ticket?” always has an answer.

Third parties

Everyone who ever touches your data.

The complete list, what each one is in law for the data it gets, and the condition under which it sees anything at all. Most never activate unless you turn the matching feature on. Not all of them are our subprocessors: a payment provider is its own controller for fraud and regulatory checks, and a mailbox or channel you connect stays your own provider — so the table says which is which rather than flattening all three into one word.

ServiceRoleEntityWhat it handlesWhen it appliesWhere
HostingerOur processorHostinger International Ltd (Lithuania)Runs the application and stores the database, the attachment files and the backups. Also relays the platform’s own transactional email — sign-in, billing and system notices.Always. This is where AGA CRM lives.Servers in Manchester, United Kingdom.
Google (Gmail API)Your providerThe mailbox is yours and so is the Google agreement covering it. We read and send through it on your instruction.Google Ireland Ltd / Google LLCReads incoming support mail and sends the replies your agents write.Only when a Gmail or Google Workspace mailbox is connected.EU and United States.
Your own mail hostYour providerWhichever provider you chooseThe same job over IMAP and SMTP for Hostinger, Outlook, Zoho or any other host.Only when you connect a non-Google mailbox. You pick this one, and it stays your contract, not ours.Wherever your provider operates.
Anthropic (Claude)Our processorAnthropic PBC (United States)Receives the ticket conversation to draft a summary, a suggested reply or a category. Nothing is sent automatically and nothing is used to train a model.Only while the AI assistant is switched on, which is off until an administrator turns it on. It can be disabled entirely.United States.
TwilioOur processorOur processor for carrying the call. Like any carrier it also has its own regulatory records of connecting it, which are not ours to instruct.Twilio Inc. (United States) / Twilio Ireland LtdCarries inbound and outbound calls, and produces recordings and transcripts where your workspace enables them.Only when your team places or receives a call through the CRM.EU and United States.
MetaYour providerYou connect the account, under Meta’s terms with you. Meta is its own controller for what it does with platform data, which no term of ours reaches.Meta Platforms Ireland LtdDelivers WhatsApp, Messenger and Instagram conversations into tickets, and sends your replies back.Only when one of those channels is connected to your workspace.EU and United States.
TelegramYour providerYour bot, under Telegram’s terms with you; Telegram is its own controller.Telegram Messenger Inc.Delivers Telegram conversations into tickets and sends your replies back.Only when a Telegram bot is connected to your workspace.Outside the EEA and the UK.
StripeIndependent controllerOur processor for taking the payment, and its own controller for fraud screening, anti-money-laundering checks and the records its regulators require. We cannot instruct it out of those, and its own privacy notice governs them.Stripe Payments Europe Ltd / Stripe Inc.Takes the subscription payment and stores the card. It receives the billing contact and the amount — never a ticket, a customer record or an attachment.Only on the billing path, when you pay by card.EU and United States.
FlutterwaveIndependent controllerThe same split as Stripe: our processor for the payment, its own controller for fraud, AML and regulatory records.Flutterwave Inc. / Flutterwave Technology Solutions Ltd (Nigeria)The alternative payment route, for the same purpose and the same fields as Stripe.Only on the billing path, and only if you choose it at checkout.Nigeria and United States.

This same list is annexed to our Data Processing Agreement, which binds each of these parties to terms no weaker than our own and commits us to 30 days’ notice before a new one starts processing. AGA CRM’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is never used for advertising and never sold.

Your controls

Switches that are actually yours to flip.

Turn AI off

One switch in workspace settings and no ticket content is ever sent to a model. Suggestions are reviewed by a human before sending in any case. Nothing is auto-sent.

Revoke mailbox access

Disconnect from the CRM, or from your Google account directly. Either one stops the sync immediately.

Export everything

Reports export as CSV and PDF, and your support data stays exportable for 30 days after a subscription ends.

Ask us to delete it

On written request from your administrator, the workspace and its data are deleted.

Running a security review on us?

Send the questionnaire. We answer it ourselves, and we say so when the answer is no.