You know where your data lives.
Most CRM security pages say "enterprise-grade protection" and move on. We wrote ours concretely: which country your data sits in, who can reach it, how far we can tell who changed which record — and which third parties touch your data, every one by name and country.
The foundation of the architecture.
A separate database per customer
Every customer runs in its own separate database. Not a "company ID" filter in a shared table — each customer's data sits in its own database, and the application routes each request to the right database based on the web address it arrives at. One exception we state openly: the application's technical error logs are kept in a single table shared by all customers.
Hosted in the EU, stated openly
The database is in Helsinki (Finland), the files you upload are in Frankfurt, and database backups are in Falkenstein — all three inside the European Union. We have no component in Turkey and no region-selection feature. Seen from Turkey this is a transfer abroad under Article 9 of KVKK; we establish the basis for that transfer together with you during the contract process.
Field-level audit trail
A separate history row is kept for every field change users make to an existing record — the time, the old value, the new value (protected fields: a marker, not the values). The record's initial creation and some bulk updates the system makes in the background are not recorded. Field history is on by default across every object that ships in a standard install; you do not need to enable it.
Recycle bin
Deletion is soft deletion: the record does not leave the database at once, it moves to the recycle bin, where an authorised user can restore it. The bin's 30-day clean-up is not running, so older records stay there too. Bulk restore is not working at the moment; records are restored one at a time. An authorised user can permanently delete records from the bin.
Access, identity and the third parties that touch your data
| Control or party | How and where it works |
|---|---|
| Two-factor authentication (2FA) | On by default for every user. The default method is an email code; an authenticator app is also supported (set up with a QR code, backup codes). |
| API authentication | OAuth2; API client secrets are stored as one-way hashes. Each API client can be granted read, write and delete scopes separately; the server checks these scopes on the general record API (create, update, delete and bulk record operations), on quote creation and on message sending. Every customer has its own separate database; automated tests check that an access token issued for one customer is rejected on a request made to another customer's web address. |
| Roles and sharing | Record visibility is controlled with role-based access and sharing rules; field-level hiding is supported. |
| Brute-force protection | Login attempts are limited both per user and per IP address (10 attempts in 15 minutes), and two-factor authentication allows 5 attempts. The counters are kept atomically. |
| Rate limiting | The mechanism is in place: once a limit is exceeded the request is rejected with a 429 and a Retry-After header. Usage analytics show you how many requests each integration is making. We have no published fixed quota figure. |
| Encryption | Browser connections to Rapitek CRM are redirected to HTTPS and encrypted with TLS; in our 23 September 2026 measurement TLS 1.3 and 1.2 were accepted and TLS 1.0 and 1.1 were refused. Passwords are not stored in plain text: they are hashed one-way with PBKDF2-SHA256 and cannot be reversed; API client secrets are stored as one-way hashes too. Email account OAuth tokens; WhatsApp Business, Instagram and Meta access tokens and webhook secrets; payment and İYS provider credentials; two-factor authentication secrets and backup codes; and voiceprints are encrypted at the application level before they are written to the database. Encryption at rest is not applied to the whole database — we do not claim that: the database files are not additionally encrypted on the server's disk. |
| Backups | Rapitek CRM database backups are taken automatically every six hours; each run checks that the dump completed without error and that the compressed file can be opened; the content of the copy sent to Germany is not additionally compared against the original. Local copies on the server are deliberately kept unencrypted and retained for 30 days. The off-server copy sits in a separate country, Germany (Falkenstein): database backups sent since 2 September 2026, 03:11 Turkey time, are encrypted with OpenPGP before they leave the server, and the decryption key is not on the production server; database backups sent before that are unencrypted. Encrypted off-server backups are deleted automatically after 90 days; the unencrypted backups kept there are not covered by this automatic deletion. This 90-day period keeps the newest 28 copies of every database regardless of their age, so that the last copies are not deleted as well if backups stop or fail; as a result, the last 28 copies of the database of a customer whose account has been terminated are not deleted by this period, and today there is no separate step that deletes them. Files attached to a record (for example, CVs) are not deleted from storage (DigitalOcean Spaces, Frankfurt) whether you delete the file from the record card or delete the record; today the product does not delete these files by itself. To have them deleted, you need to write to our support team. We have verified a restore once: on 19 August 2026 a manually taken database dump was restored into a temporary schema and 239 of 239 tables came back. No restore has yet been attempted from the automatic backups — neither from the local copies nor from the encrypted off-server copies — and we do not commit to any restore time. |
| Subprocessor — Cloudflare, Inc. | Content delivery network, TLS termination, web application firewall and bot protection · the edge server nearest the visitor, company in the United States. It is in the path of every request and the TLS connection terminates at the edge rather than at the hosting server, so data in transit and the visitor's IP are processed at that layer. No content is stored there. The requests we measured went through EU edge nodes (Amsterdam from Turkey, Stockholm from Helsinki); the node is chosen by proximity to the visitor and is not fixed. |
| Subprocessor — Hetzner | Application server and database · Helsinki, Finland (EU) |
| Subprocessor — Hetzner Storage Box | Database backups · Falkenstein, Germany (EU) |
| Subprocessor — DigitalOcean Spaces | Files and media you upload · Frankfurt, Germany (EU) — those attached to a record stay here whether you delete the file from the record card or delete the record; to have them deleted, write to our support team |
| Subprocessor — Amazon SES | Delivery of system email · Frankfurt, Germany (EU) |
| Subprocessor — Sentry | Application error monitoring · Germany (EU). Configured not to send personal data. |
| Subprocessor — Anthropic (Claude) | The Rapi AI assistant, only if you top up credit and enable it · United States — an Article 9 KVKK transfer |
| Subprocessor — Meta Platforms Ireland Ltd. | WhatsApp Business and Instagram messaging, only if you connect those channels · Ireland, with onward transfer to the United States. Message content and the other party's number or account pass through Meta's infrastructure. |
Where the legal counterpart of this page lives
Every technical statement on this page has a legal counterpart, and we wrote those out one by one on separate pages.
The full list of parties that touch your data is in the subprocessor table above; who each transfer goes to, to which country, and on what legal basis is set out one by one in Sections 8 and 13 of our Privacy Policy. The obligations we take on contractually, and the limits of each one, are on the Terms of Service page. Our KVKK Privacy Notice covers the notice we give for data that reaches us through the forms on this site.
During an enterprise evaluation, the same team that builds the product fills in your security assessment forms; if you ask about something beyond this page, we answer it in writing.
What each plan covers, on one page
Three tiers, a scope table and separately priced items — with the numbers. Scope and any setup fee are worked out in the discovery call and shared in writing.
We publish the figures rather than asking you to request them.
Frequently asked security questions.
Where exactly is our data kept?
Do you claim GDPR compliance?
Do you sign a data processing agreement (DPA)?
Where does the Rapi AI assistant send our data?
Can another customer see our data?
Can Rapitek staff reach our data?
Can we see who changed what?
Will you tell us if there is a data breach?
Do you hold a security certification?
Do you give a written uptime commitment?
Have you had an independent penetration test?
Can a record deleted by mistake be recovered?
What happens to an employee's data when they leave?
Can we get our data whenever we want?
Who answers support requests?
Can you support our teams in other countries?
Ask our team your security questions.
We fill in enterprise buyers' security assessment forms and walk through the architecture on a screen share. A technical conversation, not a sales call.
The team that builds the product answers your questions
