Trust center
The questionnaire, answered first
Current posture at a glance
| Area | Status | Evidence |
|---|---|---|
| Encryption (transit/rest) | TLS 1.2+ / AES-256 | Security page |
| RBAC + field/row-level security | Live | Security page |
| Audit logging | Live, user-visible | Sandbox audit trail |
| SSO/SAML + MFA | Enterprise plan | Pricing |
| GDPR/CCPA rights tooling | Export & deletion self-serve | Privacy policy |
| DPA | Standard template, signable | DPA |
| Subprocessor list | Published, change-notified | Subprocessors |
| SOC 2 Type I | Audit engaged — Q4 2026 | Roadmap |
| Penetration test | First annual test Q4 2026; summary will publish here | — |
| Uptime / status | Public status page + SLA | Status |
Availability commitments
| Plan | SLA | Remedy |
|---|---|---|
| Starter / Professional | 99.9% monthly | Pro-rated service credits |
| Enterprise | 99.95% monthly | Service credits + termination right after 3 consecutive misses |
Live components and 90-day history: status.glimecrm.com.
The no-lock-in guarantee
"Easy to leave" is a feature, and it's published so it can't quietly disappear:
- Self-serve full export, any time: Settings → Your data → Export. Every record, related object, and your complete audit log in documented JSON (CSV per object also available). No support ticket, no retention call.
- On cancellation: your workspace becomes read-only for 60 days with export still available, then data is deleted — with written confirmation.
- On request: deletion executes within 30 days at any time under GDPR/CCPA, including backups on their rotation schedule.
- No exit fees. No export throttling. No "talk to your account manager."
Test it in the sandbox — the export button works there too.
Documents & contacts
- Security overview · Privacy policy · Terms of service · DPA · Subprocessors
- Security questionnaires (CAIQ/SIG): security@glimecrm.com — completed within 5 business days.
- Vulnerability reports: security@glimecrm.com (24h acknowledgment).
- Privacy requests: privacy@glimecrm.com.