Skip to content
Security and compliance

Built and run by an
ISO certified company.

Eleserv Softech Pvt Ltd, the company behind Customer360, is certified to ISO/IEC 27001 for information security and ISO/IEC 20000-1 for IT service management. Here is what that means for your data, and what the product does every day.

  • ISO/IEC 27001
  • ISO/IEC 20000-1
  • India or your own database
Certifications

What the two certificates mean for you

Both are audited by an independent certification body, and both are checked again on a regular cycle, so they are not a one-time badge.

ISO/IEC 27001: information security

An auditor checks how we find security risks, decide what to do about them and prove that our controls work. It covers people, process and technology, not just servers.

ISO/IEC 20000-1: service management

The same kind of audit for how we run the service: how changes are made and released, how problems are handled, how capacity is planned and how we work with suppliers.

Certificates you can read

The certificates are issued to Eleserv Softech Pvt Ltd and name what they cover. Ask us and we will send you the certificate copies and the scope statement for your vendor review.

In the product

How Customer360 protects your data

These are things the platform does for every workspace. Security is not a paid add-on.

Strong sign-in

Passwords are hashed with Argon2id and checked against known breaches. Any user can add two-factor login with an authenticator app, and our own admin team must use it. Accounts lock after repeated failed attempts.

Roles and per-site access

Admin, manager and user roles, custom roles, and access limited to the sites a person works on. Nobody can give someone more access than they hold themselves.

Workspaces kept apart

Every database query is limited to your workspace and site by the data layer itself, not just by the screen. On Enterprise you can keep analytics in your own MongoDB database.

Encryption

Connected-app secrets and contact details are encrypted at rest with AES-256-GCM. Everything travels over HTTPS with HSTS. We do not store raw IP addresses.

Audit log

Sign-ins, role changes, exports, API keys, domain changes and views of personal data are recorded, and your admins can read them. Entries are kept for about 13 months.

Abuse protection

Rate limits on sign-in, sign-up, forms and the API, bot checks on public forms, a strict content security policy and guards against server-side request forgery.

Data stored in India

Your analytics data is stored in India (Mumbai) by default. On plans that include it you can connect your own database in the EU, the US or any other country. Visitors are covered by the consent rules of where they are.

Consent kept as proof

Every cookie choice is stored for 5 years. The banner follows opt-in rules for India and the EU and opt-out rules for US states.

Export and erase

Download your reports, erase a visitor on request, or delete your account. Data of a closed workspace is erased from our systems within 90 days, as the DPA states.

Running the service

When something goes wrong

A service standard is mostly about what happens on a bad day. This is ours.

  1. 01

    We notice

    Errors are grouped and sent to our team by email and in-app alert. Health checks watch tracking, dashboards and scheduled jobs.

  2. 02

    We tell you

    Our team can post a notice on the status page, and announcements can reach affected workspaces in the app and by email.

  3. 03

    We fix it the careful way

    Changes pass automated checks before release, and every admin action on our side is written to an audit log.

  4. 04

    We notify you about personal data

    If personal data in your workspace is affected, we tell you without undue delay and within 72 hours, as our DPA states.

Security questions

Questions from security reviews

?Is Customer360 itself ISO certified?

Eleserv Softech Pvt Ltd, which builds and runs Customer360, holds ISO/IEC 27001 and ISO/IEC 20000-1 certificates. The certificates are issued to the company and name a scope. Contact us and we will send the certificate copies and the scope statement.

?Can you fill in our vendor security questionnaire?

Yes. Send it through the contact page and choose the sales topic. We answer from our own controls and can share the certificates and the DPA with it.

?How do I report a vulnerability?

Use the contact page, pick the topic Other and start your message with Security report, or write to the address in our security.txt file at /.well-known/security.txt. Please give us a reasonable time to fix the problem before you share details publicly.

?Does Customer360 send my data to an AI service?

Only if an admin turns on AI summaries for the workspace, and it is off by default. Then only aggregate numbers go to the AI provider, never individual visitors or contact details.

?Where is my data stored, and who can reach it?

In India (Mumbai) by default, or in your own MongoDB database in any country on plans that include it. Our staff cannot sign in as you. Support can use a read-only view that needs a written reason, lasts 30 minutes, is logged and tells your organisation.

?What do I get with the DPA?

The Data Processing Agreement sets out what we process for you, the security measures, how we handle sub-processors, breach notice within 72 hours and deletion when you leave. You can read it without signing in.

Keep exploring

The detail behind this page

Need a certificate or a security review?

Tell us what your team needs and we will send it, or set up a call with the people who run the platform.