Your customer data and contracts run on infrastructure designed for SOC 2 Type II + DPDP Act 2023 + GDPR. Below is the actual posture, not marketing aspiration.
crm_*table has Postgres RLS enabled with explicit policies. Members can only read their own org’s rows. Service-role access is gated behind a wrapper that requires a documented reason per use site.no-admin-client-in-api. Direct service-role imports require a documented reason.require-assert-org-ownership. Every server action must verify resource ownership before mutation.require-anthropic-meter. Direct AI SDK calls must go through the metering wrapper.no-tenant-insert-without-org-id. Every insert into a tenant table includes org_id explicitly.crm_consent_records). Append-only, RLS-locked, covers 8 purposes (transactional, marketing, AI processing, analytics, third-party sharing, etc.). DSAR endpoints (/api/v1/dsar/export, /api/v1/dsar/delete) are operational.crm_audit_logs row with the diff. Log is partition-pruned at the configured retention window./api/cron/cron-healthruns every 30 min and flags any cron whose last successful run is > 2× its schedule interval. Monitored externally.database-backup-restore.md.We complete vendor security questionnaires within 5 business days. Email security@trendnautlabs.in with the questionnaire attached.
See how Trendnaut compares to Salesforce / HubSpot / Zoho →