Security & Trust Center
Security practices and trust center.
Last updated: July 2, 2026 · SellioCRM, LLC
Language
This document is provided in English, which is the authoritative version; any translation is for convenience only and the English version prevails.
This document applies to the customer relationship management software-as-a-service platform, websites, applications, APIs, software, documentation, dashboards, reports, artificial intelligence features, support, and related services made available by SellioCRM, LLC, a limited liability company.
For purposes of this document, "SellioCRM," "Company," "we," "us," and "our" mean SellioCRM, LLC. "Customer," "you," and "your" mean the person or entity accessing or using the Services. If you access or use the Services on behalf of an organization, you represent and warrant that you have authority to bind that organization, and that organization is the Customer.
This document is incorporated into and forms part of the SellioCRM Terms of Service unless expressly stated otherwise.
This Security Policy / Trust Center describes SellioCRM's security commitments, shared responsibility model, and general safeguards for the Services. It is provided for transparency and does not create warranties, service levels, or guarantees unless expressly stated in a signed agreement.
1. Security Philosophy
SellioCRM provides CRM software and recognizes that Customer Content may include sensitive business, sales, customer, prospect, communications, and personal information. SellioCRM uses commercially reasonable administrative, technical, and organizational safeguards designed to protect the confidentiality, integrity, and availability of the Services.
No system is perfectly secure. Customer remains responsible for its own systems, users, configurations, content, devices, networks, email accounts, integrations, access decisions, and business controls.
2. Shared Responsibility Model
SellioCRM is responsible for securing the infrastructure, application, personnel processes, and service operations under its control.
Customer is responsible for:
- configuring the Services appropriately
- managing users, roles, permissions, authentication, and workspace access
- protecting credentials, devices, networks, endpoints, email accounts, and connected systems
- ensuring Customer Content is lawful, accurate, and appropriately classified
- reviewing exports, integrations, external sharing, email sending, automations, and AI outputs
- maintaining backups and records outside the Services where required
- implementing Customer's own privacy, security, and business controls
3. Access Control
SellioCRM applies least privilege principles to personnel access where feasible. Access to production systems and Customer Content is limited to authorized personnel with a business need, subject to confidentiality obligations and access controls.
Customer should enable strong authentication, limit administrative access, review users regularly, and promptly revoke access for users who no longer require it.
4. Encryption
SellioCRM uses encryption in transit for supported connections. SellioCRM may use encryption at rest or equivalent safeguards for stored data depending on architecture, provider capabilities, and service configuration.
Customer is responsible for protecting files before upload where additional encryption, redaction, or classification is required by Customer policy or law.
5. Hosting and Infrastructure
The Services may be hosted using reputable cloud infrastructure, hosting, compute, database, storage, traffic delivery, monitoring, communications, email delivery, AI, and security providers. SellioCRM may add, replace, or remove providers as needed to operate, secure, scale, and improve the Services.
Infrastructure Resources may be shared, dedicated, serverless, managed, or provider-operated depending on service architecture and Customer configuration.
6. Logging and Monitoring
SellioCRM may collect logs, telemetry, alerts, and diagnostic information to operate the Services, troubleshoot issues, detect abuse, investigate incidents, monitor performance, measure infrastructure usage, calculate Infrastructure Charges, and improve security.
Customer should monitor its own Account activity, user access, exports, integrations, automations, email usage, AI usage, and internal use of Service outputs.
7. Vulnerability Management
SellioCRM uses commercially reasonable processes to identify, evaluate, prioritize, and remediate vulnerabilities in systems under its control. Remediation timelines depend on severity, exploitability, impact, compensating controls, and operational risk. Customers and researchers may report suspected vulnerabilities to contact@selliocrm.com.
8. Secure Development
SellioCRM aims to use secure development practices appropriate for SaaS services, which may include code review, access control, dependency management, testing, environment separation, change management, and security review of material changes.
9. Backup and Recovery
SellioCRM may maintain backups or redundancy depending on architecture, provider capabilities, and service configuration. Backup schedules, retention, restoration time, and data recoverability may vary.
Customer should maintain independent copies of critical business records, exports, communications, and Customer Content where required by Customer policy, law, or business continuity needs.
10. Incident Response
SellioCRM maintains processes to identify, investigate, contain, mitigate, and communicate security incidents affecting systems under its control. Customer is responsible for incidents involving Customer systems, credentials, devices, email accounts, integrations, exports, or misuse of the Services.
11. Personnel Security
Personnel with access to systems or Customer Content are expected to be subject to confidentiality obligations and access controls appropriate to their roles. SellioCRM may use contractors and service providers subject to appropriate obligations.
12. Vendor and Subprocessor Security
SellioCRM may use vendors and Subprocessors to operate the Services. SellioCRM evaluates vendors based on risk and imposes contractual obligations where appropriate. Customer acknowledges that providers may operate components of the infrastructure used to provide the Services.
13. Customer Security Recommendations
- use strong authentication and unique passwords;
- restrict administrative privileges
- review users, roles, exports, API tokens, and integrations regularly
- protect connected email and calendar accounts
- avoid uploading unnecessary sensitive data
- monitor unusual activity, mass exports, failed logins, and suspicious automations
- maintain independent backups of critical business data
- train users on phishing, data handling, and CRM access practices
14. No Security Guarantee
SellioCRM does not guarantee that the Services will be secure, uninterrupted, error-free, immune from attack, or free from vulnerabilities. Security is a shared responsibility and depends on Customer configuration, user behavior, connected systems, third-party providers, and evolving threats.
15. Contact
Security questions and vulnerability reports may be sent to legal@selliocrm.com.