GlassHand GlassHand CRM
All systems operational

Trust & Security

How GlassHand CRM protects your business data and your clients' information — in plain language, kept current as our infrastructure evolves.

How your data is protected

Your data stays yours

Every business's contacts, invoices, and messages are isolated from every other business — enforced at both the application and database level.

Encrypted in transit

All traffic to and from GlassHand CRM is encrypted via HTTPS/TLS — nothing is ever sent in plain text.

Independent security review

Our systems undergo regular internal security audits covering authentication, data isolation, and third-party integrations.

Payments never touch our servers

Card details are handled entirely by Stripe — GlassHand never stores or has access to raw payment information.

Where we stand today

We'd rather be specific than vague. Here's our honest, current security posture:

LiveEncrypted connections (HTTPS/TLS) on every request
LivePayment processing fully delegated to Stripe — no card data on our servers
In progressDatabase-level tenant isolation (row-level security) as a second layer beneath application checks
In progressWebhook signature verification across all integrations
PlannedIndependent third-party penetration test
PlannedSOC 2 Type I readiness assessment

Questions about security?

We take data protection seriously and are happy to answer specific questions about how your business's information is handled. Reach us directly at security@glasshandcrm.com.