Enterprise-grade security

Your data is protected
by design, not by luck.

Graciax is built with security at every layer. From 256-bit encryption to DPDPA compliance, your CRM and HR data stays private, safe and under your control. And the AI runs on a leash you hold.

256-bit SSL Encryption 99.9% Uptime SLA SOC 2 Type II Certified ISO 27001:2022 DPDPA 2023 Compliant AI: PII redacted, approval-gated
Compliance & certifications

Security you can verify

Every layer of Graciax is built with security-first principles. Here is what protects your data, and where each certification comes from.

Vercel · SOC 2 + ISO 27001 + GDPR Supabase · SOC 2 Type II + HIPAA Graciax · DPDPA + OWASP + RBAC

256-bit SSL Encryption

TLS 1.3 in transit, AES-256 at rest

SOC 2 Type II

Both Vercel + Supabase certified

ISO 27001:2022

Vercel certified hosting

DPDPA 2023

India data protection compliant

GDPR Ready

Vercel EU-US Data Privacy Framework

OWASP Top 10

XSS, CSRF, injection protected

99.9% Uptime SLA

Redundant, auto-healing infra

Data Hosted in India

AWS Mumbai (ap-south-1)

Role-Based Access

Row-level security + 4 roles

Full Audit Trail

Every action logged with IP

Global Edge Network

Vercel CDN with DDoS protection

TISAX AL2

Vercel high-protection certified

Defence in depth

How we protect your data

Six layers of security that work together so you can focus on running your business.

Data Encryption

  • HTTPS with TLS 1.3 on all connections
  • AES-256 encryption for stored data
  • Isolated production environments
  • Encrypted database connections (SSL)

Account Security

  • Passwords hashed with bcrypt
  • Two-factor authentication (2FA)
  • Auto-logout on inactivity
  • Suspicious login alerts

Infrastructure

  • Supabase (SOC 2 Type II certified)
  • AWS Mumbai region (ap-south-1)
  • 24/7 automated monitoring
  • Auto-scaling with zero downtime

Backup & Recovery

  • Daily encrypted backups
  • Point-in-time recovery (PITR)
  • Geo-redundant storage
  • Full restore within 24 hours

Access Controls

  • Row-level security (RLS) on all tables
  • 4 permission roles (Admin, HR, Mgr, Emp)
  • Permission-based support access
  • No third-party data sharing

Regulatory Compliance

  • DPDPA 2023 (India) aligned
  • OWASP Top 10 protections
  • Full audit trail with IP logging
  • Regular dependency patching
AI safety

Autonomy with a leash you hold.

Graciax puts AI on the phone with your customers and inside your pipeline. So every model call is redacted, every write is gated, and every action is logged and reversible.

PII redactionNames and phone numbers never reach the model

Before a prompt is built, people become tokens. The model reasons over the redacted record. Anything that touches a real person runs as a tool call inside your own workspace, not at the AI provider. Bring your own model key if you prefer.

CRM recordRahul Kumar · +91 98XXX 12345 · Housing.com
What the model sees[PERSON_1] · [PHONE_1] · Housing.com

Approvals queueReads are free. Writes wait for you.

Anything that sends, spends or hires shows an approval card first. You loosen it per agent, never by default.

Approve before sending to customers
Message leads directly

UndoReplays an agent’s writes in reverse

Every run keeps the list of what it changed. One tap unwinds the whole run, in order, and the reversal is logged too.

assign_lead · 14 leadsundo
update_lead · statusundo

Audit logEvery tool call, against a person

Agents, Studio threads and MCP clients all write to the same run log. Timeline entries are authored by the agent, so you always know who did what.

search_leadscreate_taskget_team_kpis

Role-scoped MCP keysA key can only see what its owner can

Keys inherit the creator’s role. Claude.ai connects with OAuth, Cursor and Claude Code with one key, and every call is audit-logged.

Admin · workspaceManager · teamUser · own

Calling complianceVoice agents that follow the rules, every call

Built into the agent, not left to configuration.

  • Consent record kept for every lead called, and do-not-call lists honoured.
  • 8am to 9pm in the lead’s timezone, never outside.
  • “Stop calling me” revokes consent instantly, mid-call.
  • Non-editable AI disclosure at the start of every call. The agent always says it is AI.
Responsible disclosure

Found a security issue?

We take every report seriously. Contact our security team and we will respond within 24 hours.

support@graciax.com

Graciax reviews and updates security infrastructure, practices and policies regularly.

Join 150+ growing teams
trusting Graciax CRM

Built-in SOC 2 controls, GDPR readiness and rock-solid reliability, plus the productivity gains your team craves.

★★★★★
Graciax’s end-to-end AES-256 encryption and strict SOC 2 controls let us migrate highly sensitive lead data with confidence. Zero incidents in 18 months. Our board finally sleeps at night.
Jonathan Lee
CTO, Vertex Solutions
★★★★★
Role-based access controls and real-time audit logs make GDPR audits painless. Security tickets solved in <30 min. That’s a partner you can rely on.
Priya Kapoor
Chief Information Security Officer
★★★★★
The UI is as intuitive as email. New hires ramp in 30 minutes. Unlimited-user pricing means we scale freely across our franchise network without surprise costs.
Laura Williams
Operations Manager
★★★★★
OAuth 2.0 SSO and mandatory 2FA rolled out to 150+ reps in a day. No more password-reset chaos. All API traffic is TLS 1.3-only, exactly what our auditors demanded.
Carlos Reyes
IT Manager
★★★★★
Pipeline stages are crystal-clear, and automated follow-ups lifted conversions by 32% in one quarter. The single-pane dashboard keeps our entire sales floor in sync.
David Chen
Sales Director
★★★★★
Daily encrypted backups across geo-redundant regions meet our toughest data-residency clauses. Point-in-time restores saved us after an accidental bulk delete.
Anna Müller
Data Protection Officer
Get started

AI you can put
in front of customers.

Book a demo and see the approvals queue, the run log and the redaction for yourself, on a test lead.