Security
How your CRM is accessed, where your data is hosted, who can see it — and what we have not done yet.
Last updated: August 3, 2026
1. Our principles
We would rather publish a page you can check than a page that merely reassures. What follows describes the real state of the service, including what is not yet in place.
- As little data as possible. We do not copy your CRM: we keep aggregate metrics and a limited number of real examples, needed to back up each finding.
- As little access as possible. Each process runs with only the permissions it needs, and you can withdraw them at any time.
- Nothing irreversible without you. Changes proposed by agents wait for your approval before being applied to your CRM.
2. Access to your CRM
We never see your credentials
The connection uses your CRM's official authorisation mechanism (OAuth 2.0). You authenticate with your vendor, never with us. We receive a revocable access token, never your password.
The audit changes nothing
The free audit performs read operations only on your CRM. No writes, no deletions, no record creation take place during the analysis.
One important point about the authorisation screen. The current connection also requests write permissions, because the same access is later used by the cleaning and enrichment agents. You will therefore see those permissions listed when authorising, even though the audit does not use them. We would rather tell you here than let you discover it: no write happens until you enable an agent and approve its proposals.
You cut off access whenever you want
Disconnecting from your settings immediately deletes the access tokens from our database. You can also revoke the application directly from your CRM, without going through us: revocation takes effect with no action needed on our side.
3. Hosting and encryption
- Encrypted transport. All communication, between your browser and the service and between the service and your CRM, is encrypted with TLS. The service is only reachable over HTTPS.
- Application data hosted in France. The database and file storage are operated by Scaleway, in France.
- Passwords. They are never stored in clear text or reversibly encrypted: only a bcrypt hash is kept. We are therefore technically unable to recover your password.
- Workspace isolation. Every request is bound to the session's workspace: one customer's data is not reachable from another customer's account.
4. Our team's access
Access to production systems is limited to the people who need it to operate the service or handle a support request, and is used only for those purposes.
We do not look at the content of your CRM outside an operational need or a request from you. The related technical logs are kept for 12 months.
5. Providers
The service relies on a limited number of providers, whose role, the data involved and their location are set out on the Subprocessors page. Each is bound by a contract meeting article 28 GDPR.
6. In case of an incident
In the event of a data breach likely to create a risk for the individuals concerned, we inform affected customers without undue delay and, in any case, as soon as possible after discovering the incident, with the information available to us: nature of the incident, data involved, measures taken.
Where we act as a processor, that notification allows you to meet your own obligation to notify the CNIL within the 72-hour window set by article 33 GDPR.
7. What we do not have yet
We are a young company. Rather than display certifications we do not hold, here is the real state of play.
- SOC 2 and ISO 27001 certifications: we hold neither, and no process is under way to date. We claim no compliance with those frameworks.
- Application-level encryption of CRM access tokens: tokens are protected by the hosting and access-control measures of the database. An additional application-level encryption layer is being put in place.
- Two-factor authentication: not yet offered on accounts. It is on our roadmap.
- External security audit and paid responsible-disclosure programme: neither has been carried out to date.
This section is updated as the work progresses. If any of these points is a blocker for your organisation, write to us: we would rather discuss it before you connect anything.
8. Reporting a vulnerability
If you believe you have found a security flaw, write to hello@jipup.com with the technical details needed to reproduce it. We acknowledge receipt within 72 business hours and keep you informed of the outcome.
We undertake not to take action against anyone who reports a flaw in good faith, without exfiltrating data, without degrading the service, and without publicly disclosing the flaw before it is fixed.