Security and compliance.

How your data is separated, protected, backed up and recovered.

Security and compliance at Clockwork CRM

This page describes the measures behind Annex 2 of our Data Processing Agreement.

A separate database for every customer

Your data is held in a separate, dedicated PostgreSQL database, owned by a database role and credentials unique to you. Your uploaded files sit in a separate storage container. There is no shared table holding several customers' records, and no application-level filtering deciding which rows you are allowed to see.

The per-customer databases sit on shared infrastructure, so a compromise of that infrastructure would reach everyone, and we treat any incident touching that layer as critical by default. And files published for public access, such as email template headers and product images, sit in a shared container separated by path rather than by container. That area holds branding and product imagery rather than CRM records.

Hosting

  • Microsoft Azure, United Kingdom (UK South)
  • Production roles are separated across dedicated machines: application and reverse proxy, database, background job processing, and realtime messaging
  • Each machine permits only the ports its role requires. Database and administrative ports are restricted to named addresses and are not reachable from the public internet
  • Azure platform DDoS protection on all public endpoints

Access control

  • Role-based access control inside the application, administered by you, including a separate administrator role
  • Two-factor authentication is available to every user, and an administrator can require a given user to enrol
  • Password policy enforced at set and reset: minimum 8 characters with upper case, lower case, numeric and special characters
  • Our access to production is limited to named individuals on a least-privilege basis, requires multi-factor authentication, and is logged. Access is reviewed every 6 months and revoked within 24 hours when no longer needed

Encryption

  • In transit: TLS 1.2 and 1.3 only. HTTP Strict Transport Security enabled, HTTP redirected to HTTPS, session cookies marked Secure
  • At rest: database disks, file storage and backups are encrypted with AES-256
  • Application secrets, including per-customer database credentials and storage keys, are held in Azure Key Vault and encrypted at the application layer with AES-256 under a PBKDF2-SHA256 derived key
  • Two-factor authentication seeds are encrypted at rest with a key held in Azure Key Vault
  • Passwords are hashed with Argon2id, the memory-hard algorithm recommended by OWASP, using a random per-password salt and parameters at or above OWASP's current guidance. Passwords are never stored or recoverable in readable form
  • Card details are never received or stored by us. Payment card data is collected directly by our payment processor and we hold only their tokens

Backup and recovery

  • Every customer database is dumped individually, every two hours, stored encrypted in the UK and retained for 30 days. Because the dumps are per-database, your instance can be restored on its own without involving anyone else's data
  • All production machines are additionally backed up daily at 02:00 UTC, retained as 10 daily, 4 weekly and 3 monthly restore points
  • Restores are tested at least annually
  • Recovery point objective: up to 2 hours. Recovery time objective: 8 hours

Monitoring and audit

  • Application error and performance monitoring with automated alerting
  • Infrastructure alerting on every production machine covering availability, CPU, memory, disk saturation and network throughput
  • Field-level change history within the application for core record types, giving a per-record audit trail of what changed, when, and by which user

Privacy built into the product

  • Website analytics in Clockwork CRM are first-party and cookieless. Visitor identity is a keyed hash of site, IP address and user agent under a salt rotated daily and discarded after about two days. Raw IP addresses and user agent strings are never stored, and no tracking cookie is set
  • IP-to-location lookup happens offline against a database on our own servers, so no visitor IP address is sent to a third party

Secure development

  • Separate development, staging, pre-production and production environments, deployed through an automated pipeline
  • All changes reach production through a reviewed merge request, with an automated suite of over 2,300 tests run on every build
  • Live customer data is never copied into development or staging. Those environments use generated test data
  • Dependency vulnerability scanning runs as part of the build

Incident response

We maintain a documented security incident and personal data breach procedure, given contractual effect by clause 8 of our Data Processing Agreement. The commitments that matter to you:

  • We notify you of a breach affecting your data within 48 hours of becoming aware, at any time of day
  • For critical incidents we aim to make first contact within 4 hours during our support hours, and on a best-efforts basis outside them
  • We give you what you need for your own 72-hour obligation to the Information Commissioner. We do not report on your behalf, and we do not contact your data subjects, unless you instruct us to
  • We hold a tabletop exercise at least annually and review the procedure after every critical incident

Researchers can report a suspected vulnerability to security@mythic.software.

Certification

We hold Cyber Essentials, the UK government-backed scheme certifying an organisation against the controls that prevent the most common internet-based attacks.

Certified entityMythic Software Limited
ScopeWhole Organisation
Certified byThe IASME Consortium Ltd, through certification body Baseel
Date of certification2 February 2026
Valid to2 February 2027

The certificate is independently verifiable on the Blockmark registry, and we send a copy for your records on request.

Questionnaires and evidence

We complete customer security questionnaires on request, and will provide written evidence of any measure on this page. Annex 2 of our Data Processing Agreement sets out our technical and organisational measures in full, as binding contractual representations, including where a measure has limits.

Related

Data Processing Agreement · Sub-processor list · Privacy policy

Anything not covered here, email privacy@mythic.software.