Tenant boundary
Tenant identity is resolved through trusted server-side infrastructure and used to scope tenant-owned data.
Security and privacy
OneCRM's Constitution does not allow security, privacy, tenant isolation, auditability or customer data ownership to be traded for speed or feature breadth.
These are architecture and implementation facts, not a production certification or service guarantee. Each production environment must still prove its complete trust path.
Tenant identity is resolved through trusted server-side infrastructure and used to scope tenant-owned data.
Tenant-scoped roles and permissions use deny-by-default authorization; UI visibility is not treated as security.
Security-relevant user, role, permission and tenant-management changes create durable audit evidence.
AI and automation must respect existing authorization and retain responsible human control for consequential work.
Customer ownership, portability and provider neutrality are constitutional design principles.
DNS, TLS, proxy trust, regions, providers, backups and operational controls remain deployment-specific gates.
Confirmed principle
A tenant is the SaaS security and data-isolation boundary. An organisation is a legal or operating company within that tenant. This allows business structures to evolve without weakening the tenant boundary.
Open production decisions
Providers, regions, cross-border processing, encryption and backup commitments, certifications, service levels and final privacy wording are not approved for definitive public claims.
Final legal and privacy language requires qualified review before production publication.
Transparent by design
The platform overview keeps implemented foundations, planned capabilities and long-term vision visibly distinct.