Security
How we guard your data. In plain English.
Last updated: August 21, 2026
Your CRM holds your whole book of business, so “is it safe?” deserves a straight answer, not a wall of acronyms. Here’s exactly how FiggyCRM protects what you put in it.
Where your data lives
FiggyCRM runs on Supabase, hosted in Amazon Web Services data centers in the United States. It's the same infrastructure some of the biggest software companies in the world run on, with SOC 2 compliance at the infrastructure level.
Encrypted everywhere
Your data is encrypted in transit (TLS) and at rest (AES-256). In plain English: it's scrambled while it travels between you and us, and scrambled again while it sits on disk.
Passwords we never see
Your actual password is never stored, only a scrambled fingerprint of it. Every new password has to meet strength requirements and is checked against the public database of passwords exposed in past breaches, so a password that's already leaked somewhere can't be used on FiggyCRM.
Two-factor authentication, if you want it
Add a second lock to your account: signing in takes your password plus a 6-digit code from an authenticator app on your phone, with ten one-time recovery codes in case you ever lose it. Turn it on in Settings under Security. With it on, a stolen password alone gets nobody in.
Payments that skip us entirely
Billing is handled by Stripe, the payment company behind millions of businesses. Your card number goes to Stripe and only Stripe. It never touches FiggyCRM's servers, so it can't leak from them.
Backups, twice over
Two layers, every day: the database's own daily backups, plus FiggyCRM's separate per-workspace copies kept for 30 days. A bad day can be rolled back.
Walled-off workspaces
Every workspace's data is isolated at the database level, not just in the app's screens. Your contacts can't bleed into someone else's workspace, and theirs can't reach yours.
Not for regulated data
FiggyCRM is built for ordinary business contacts: names, companies, deals, notes. It is not built for health records, financial-account data, or other regulated information, and we do not sign HIPAA business associate agreements. If that is the data you hold, FiggyCRM is the wrong tool, and we would rather say so here than after you have uploaded it.
Who else touches your data
Six companies help run FiggyCRM, each bound by a data processing agreement: Supabase (database, authentication, and file storage), Vercel (hosting), Amazon Web Services (the infrastructure under Supabase), Stripe (payments), Resend (transactional email), and Sentry (error monitoring, with personal data scrubbed before it is stored). All six are in the United States. The same list appears in our Privacy Policy and our DPA.
Your data stays yours
Export everything anytime from Settings under Data & backups. Delete your account yourself, no phone call required: your data is removed from the live service immediately, and copies persist in routine encrypted backups for up to 30 days before being overwritten. And we never sell your data to anyone, full stop.
Data protection & GDPR.
For workspace data you are the controller and we are the processor. Our Data Processing Agreement sets out roles, subprocessors, breach notification, and international transfers, and it applies to every account automatically when you accept the Terms. No signature needed. If your organization requires a countersigned copy, email hello@figgycrm.com.
Read our Data Processing AgreementFound something? Tell us.
If you’ve found a security issue, big or small, email security@figgycrm.com. A human reads every report, and we’ll reply to yours.
If you report a vulnerability in good faith, we will not pursue legal action against you. Give us reasonable time to fix the issue before disclosing it publicly, don’t access, modify, or delete data that isn’t yours, and don’t degrade the service for others. Work within these lines and we’ll treat your report as authorized.
