For a plain-language overview of these same practices, see our Security & Trust page.
Invictus CRM is built on Google Cloud Platform / Firebase infrastructure, which maintains ISO 27001, SOC 2, and SOC 3 certifications at the infrastructure level. Data is encrypted in transit (TLS) and at rest.
Each agency's data is logically isolated from every other agency on the platform through per-agency access-control rules enforced at the database level, not merely at the application layer. An advisor can only access data belonging to their own agency and, within that, only the clients/leads they own or are permitted to see.
Data is backed up using point-in-time recovery capabilities provided by our infrastructure provider. Uptime is monitored continuously, with automated alerting for any detected downtime.
Every electronic signature completed within Invictus CRM is logged with a timestamp, the signer's IP address, and a unique certificate ID, creating a verifiable audit trail for compliance purposes. See our Electronic Signature & Records Consent statement for details.
We use a limited number of trusted third-party sub-processors to operate the platform, including:
| Provider | Purpose |
|---|---|
| Google Firebase / Google Cloud | Application hosting, database, file storage, authentication |
| Resend | Transactional email delivery |
| Stripe | Subscription billing and payment processing |
Each sub-processor only receives the minimum data necessary to perform its specific function.
In the event of a confirmed data breach affecting your personal information, we will notify affected agencies without undue delay, consistent with our obligations under PIPEDA and applicable provincial privacy legislation.
Security questions or concerns can be sent to support@invictuscrm.com.