Trust before features

Clear answers are better than premature guarantees.

OneCRM treats security, privacy, tenant isolation, auditability and customer control as product requirements. Where a production decision is still open, we say so.

Current answers

Understand both the foundation and the boundary.

These answers describe verified architecture and accepted design principles. They do not claim a production service, certification, service level or hosting commitment.

01

How does tenant isolation work?

OneCRM's implemented foundation resolves a tenant at a trusted server boundary and scopes tenant-owned data and permissions accordingly. Production deployment controls still require environment verification.

02

Can another customer's administrator see our records?

The product architecture separates tenant-local administration from platform operations. It is designed to deny access across tenant boundaries; this is not a claim of production certification.

03

Who controls our access?

Tenant-scoped roles, permissions and audited security changes are part of the implemented foundation. More advanced organisational scopes remain staged.

04

How will AI use business information?

OneCRM's accepted direction requires permission-aware, purpose-driven AI with human control. Final providers, processing locations and production policies are not yet confirmed.

05

Where will data be hosted?

No definitive public hosting or data-residency commitment has been approved. Provider and region decisions require technical, privacy and owner review.

06

What happens if we leave?

Customer data ownership and portability are constitutional principles. Detailed production export, retention and offboarding commitments remain to be approved.

Implemented foundation

Tenant-aware access and audit

The development foundation includes trusted tenant routing, tenant-scoped permissions, controlled platform administration and durable audit events. Hosted-production controls remain a separate verification gate.

Long-term vision

Open, portable and provider-neutral

OneCRM's Constitution says customers own their data and the product should avoid unnecessary lock-in. Contractual portability, retention and provider commitments require approval before publication.

Trust requires precision

Explore what OneCRM is building—without blurring product status.

See the current foundation, accepted direction and long-term vision side by side.