RS RevSprint CRM

Compliance & Security

ISO 27001 governance, data-protection requests and tight access control in the same system.

Evidence is a by-product of doing the work in the system, not a scramble before an audit. Access is limited by role, and every sensitive change leaves a trail.

What you can do

  • ISO 27001:2022 controls, risk register, incidents, non-conformities, audits, policies and a Statement of Applicability
  • A public data-request page for access and erasure requests, with email verification and a 30-day clock
  • Electronic signatures with a certificate of completion, and tamper checks on the signed file
  • Roles and permissions on every page, and records separated between companies
  • Two-factor sign-in, enforced for administrators from a date you set
  • Encrypted storage for sensitive fields, and a log of who opened the most sensitive ones
  • Scheduled, encrypted backups with a failure alert

Good to know

  • Tools help you prepare; certification still needs an auditor. The legal pages are drafts that need a lawyer's review for your business.

Try it with your own data

Set up a company and see how the modules fit together.

Get started free