Security you can explain to legal in one sentence

Hosted: Lilly runs on Qivity’s servers. Self-host: she runs on yours. Either way she is an optional AI add-on on paid plans — not on the Free trial.

Strict tenant isolation

Every organisation’s records are separated at the data layer. A query that forgets its tenant scope does not silently return someone else’s data — it returns nothing.

Encrypted credentials

Connected mailbox tokens and sensitive settings are encrypted at rest. Federated sign-ins (Microsoft 365, Google) store no password at all.

Where Lilly runs

On hosted plans, Lilly runs on Qivity’s servers. Self-host and she runs on local models inside your deployment. Lilly is an optional AI add-on on paid plans — not on the Free trial. Ask sales.

Rate limiting and sign-in protection

Brute-force protection on authentication, rate limits on public forms, and honeypots on lead capture.

Audit logging

A tamper-evident record of administrative actions, with archival controls.

Data residency

Self-hosted and private-cloud deployments run in the region your regulator requires — including inference, because it is the same box.

Application security

The product is built against the usual suspects rather than assuming a framework handles them: output sanitisation on all user-supplied HTML (email bodies and signatures included), a content security policy, signed and HMAC-verified tracking links, hardened session cookies, and CSRF protection on state-changing requests.

Access control

Record visibility follows the reporting line, not the role badge. Leads are private to their owner and the people they report up to by default. Being an administrator grants administration, not a licence to read a colleague’s pipeline — a distinction most CRMs collapse, and the reason their AI assistants leak data they were never meant to surface.

Data ownership

Your data sits in a standard PostgreSQL database. On a self-hosted deployment you can query it directly, back it up on your own schedule, and take it with you. There is no proprietary export format and no exit fee.

Reporting a vulnerability

Email sales@qivity.com with the details. We acknowledge within two business days and will not pursue researchers acting in good faith.

Detailed security documentation, including our VAPT remediation history, is available under NDA on request.

Security questions

Does Qivity send CRM data to OpenAI or any other AI provider?

Not to OpenAI, Anthropic or Google. On hosted plans Lilly runs on Qivity’s servers. Self-host and she runs on your organisation’s infrastructure. Lilly is an optional AI add-on on paid plans — not on the Free trial.

Can we self-host for data residency?

Yes. Docker, PostgreSQL and Redis, including Lilly, on your servers or private cloud — including deployments with no internet egress.

Who can see whose records?

Visibility follows the reporting line. Leads are private to their owner and the people they report up to. Being an administrator grants administration, not a licence to read a colleague’s pipeline.

Are mailbox credentials encrypted?

Yes. Mailbox credentials are encrypted at rest. Sessions use hardened cookies, and state-changing requests are CSRF-protected.

How do we report a vulnerability?

Email sales@qivity.com with the details. We acknowledge within two business days and will not pursue researchers acting in good faith. A VAPT history is available under NDA.

Send us your security questionnaire

We fill them in ourselves rather than routing you to a portal.