Security & Data Protection
1. Our approach
CoveCRM uses cloud-hosted infrastructure, HTTPS for encrypted transmission, and account access controls intended to protect information and separate customer access. Security depends on the feature, deployment, provider and account configuration. No service can guarantee complete security or prevent every incident.
This page is a general description, not an independent audit report, warranty, or claim of SOC 2, ISO, HIPAA or other certification. Any separately agreed security obligations must be stated in a written agreement.
2. Customer access and responsibilities
Use individual credentials, secure devices and email accounts, appropriate user permissions, and authorized integrations. Limit the personal information you submit to what your workflow requires. Notify support promptly of suspected unauthorized access. Account controls do not remove the need for your own security and compliance practices.
3. Communications features and limitations
Cove provides A2P registration workflows and opt-out/suppression functions in certain communication paths. These tools do not guarantee TCPA, DNC, recording, privacy or insurance compliance and should not be assumed to enforce every recipient choice across every channel. Customers remain responsible for lawful use, required permissions and supervision.
See the Acceptable Use & Communications Policy and Terms.
4. Providers, retention, and assurances
The Privacy Policy describes information handling and retention limitations. The provider register identifies supported providers and role distinctions. A DPA is available for written incorporation; its publication does not certify that a customer-specific security or transfer arrangement has been executed.
Do not assume a particular data-residency location, recovery time, backup schedule, uptime commitment or regulated-data environment unless Cove has expressly agreed to it.
5. Reporting concerns
Report a suspected security issue to support@covecrm.com or legal@covecrm.com. Provide enough information to investigate without sending passwords, credentials, or another customer's information. This invitation does not authorize disruptive testing or access to data without permission.