← Back to Invictus CRM

Data Security & Compliance Statement

Last updated: August 2026

For a plain-language overview of these same practices, see our Security & Trust page.

1. Infrastructure

Invictus CRM is built on Google Cloud Platform / Firebase infrastructure, which maintains ISO 27001, SOC 2, and SOC 3 certifications at the infrastructure level. Data is encrypted in transit (TLS) and at rest.

2. Data Isolation

Each agency's data is logically isolated from every other agency on the platform through per-agency access-control rules enforced at the database level, not merely at the application layer. An advisor can only access data belonging to their own agency and, within that, only the clients/leads they own or are permitted to see.

3. Access Controls

4. Backups and Availability

Data is backed up using point-in-time recovery capabilities provided by our infrastructure provider. Uptime is monitored continuously, with automated alerting for any detected downtime.

5. Audit Trail

Every electronic signature completed within Invictus CRM is logged with a timestamp, the signer's IP address, and a unique certificate ID, creating a verifiable audit trail for compliance purposes. See our Electronic Signature & Records Consent statement for details.

6. Sub-Processors

We use a limited number of trusted third-party sub-processors to operate the platform, including:

ProviderPurpose
Google Firebase / Google CloudApplication hosting, database, file storage, authentication
ResendTransactional email delivery
StripeSubscription billing and payment processing

Each sub-processor only receives the minimum data necessary to perform its specific function.

7. Breach Notification

In the event of a confirmed data breach affecting your personal information, we will notify affected agencies without undue delay, consistent with our obligations under PIPEDA and applicable provincial privacy legislation.

8. Contact

Security questions or concerns can be sent to support@invictuscrm.com.