01 Workspace isolation
Every company on Ledrix gets a private workspace. Leads, brands, sellers, clients, orders, and tickets stay inside that workspace. Another organization on the platform cannot open yours.
Inside the workspace, brands stay on their own pipeline. Admins see the brands in their company. Sellers see their assigned book. Clients see only their own orders.
That isolation is live for every signup: the product scopes every CRM row to your tenant (and brand). Agencies that need a dedicated CRM database — a separate database for that workspace, not only a filter — can request it. We provision that database for the workspace when the contract calls for it.
02 Who sees what
Closers should not sit in admin tools. Finance should not run the pipeline. Clients should not see another buyer’s invoice. Ledrix encodes that in roles:
- Admin — brands, sellers, keys, import, organization billing, team, export, audit log.
- Seller / closer — their book, payment links, briefs, messages. They do not get Account Keys or raw Stripe/PayPal secrets. Card numbers stay on Stripe or PayPal’s checkout — not in the seller panel.
- Finance — brand payment and payout reports only. The rest of the CRM is closed to that login.
- Client — their orders, invoices, briefs, tickets, and messages.
That is data minimization in the product: each login gets the records it needs to do the job, not the whole shop.
03 GDPR — export and erasure (live)
You remain the controller of the client data you store in Ledrix. We process it to run the product. When a client (or you, on their behalf) needs a copy or a deletion, the workspace already has a path:
- Export (live). A workspace owner requests a ZIP of CRM and billing CSVs from Organization → Data export. The request requires a written reason. Super Admin prepares the file. You download it on a signed, time-limited link. That is what you hand a client when they ask “send me my data.”
- Erasure (live). Super Admin can run a workspace erasure. The system requires a reason and writes that reason to the audit log. Access is revoked and personal fields are anonymized. Export first if you still need a copy.
- Access and correction. Email hello@ledrix.co for personal data we hold about you as a Ledrix customer. Legal basis and retention sit in the Privacy Policy.
The logged reason is the point: you can show who asked, why, and what ran — instead of hunting Slack when a client’s counsel writes.
04 Audit trails (live)
Two trails, for two jobs:
- Lead view activity (Admin CRM dashboard). When a closer opens a lead, the workspace records seller, lead, brand, time, and IP. Admins see that feed on the dashboard and can clear it. That is how you answer “who looked at this lead, and when?”
- Organization audit log. Organization → Audit log lists sensitive workspace actions: who did them, when, and a short description — data-export requests, team invites, domain changes, billing and plan events, 2FA, SSO sign-ins. Super Admin keeps a matching platform log (including impersonation).
05 Practical security (live)
- HTTPS in transit
- Hashed passwords
- Role-scoped portals (admin, seller, finance, client)
- Optional two-factor authentication on admin and seller logins; platform owners can be required to enable it
- Workspace audit log as above
06 Formal frameworks (roadmap)
SOC 2 and ISO 27001 reports are not published on this page yet. When an independent report is ready, it will appear here with a date so you can send it to a buyer.
For a signed DPA, a hosting-region conversation, or a security questionnaire on a larger deal, use the contact form. We will reply with the current pack — not a placeholder.
07 SSO and SCIM
CRM admins can sign in through your identity provider (Okta, Microsoft Entra, or any OIDC IdP). Tell us the provider when you are ready. We turn SSO on for the workspace, give you the redirect URL and client settings, and your team uses “Sign in with SSO.”
SCIM 2.0 is available on the same setup: your IdP can create, update, and deactivate CRM admin accounts at our SCIM Users API. We issue the bearer token to your IT contact.
This is a guided setup, not a self-serve “Connect Okta” button in the trial. Ask sales and we walk the steps.
08 Next step
Ledrix — hello@ledrix.co · Contact form for DPA, SSO, or a dedicated database · Try a plan free · Privacy Policy