Security Policy
Last Updated: August 20, 2026
Your leads, deals, project plans, and support tickets are core to how your business runs. Here’s how we help keep that data safe, from the moment you sign in to the moment it’s stored.
We use multi-factor authentication
Every time you or your team signs in to the Platform, we can verify your identity in more than one way — for example, recognizing a trusted device or location, and, when needed, sending a one-time code to confirm it’s really you. We recommend enabling multi-factor authentication (MFA) for every user, and administrators can require it organization-wide from the security settings page.
Your data is encrypted
Data you store in the Platform — leads, contacts, project files, and ticket details — is encrypted at rest using AES-256 encryption, and encrypted in transit between your browser and our servers using TLS. This means your information is translated into a form that only authorized systems and people can read.
Role-based access, by design
Not everyone on your team needs to see everything. The Platform lets administrators assign roles and permissions so sales reps, project managers, and support agents only access the leads, projects, and tickets relevant to their work. Every workspace is logically separated from every other customer’s data.
We keep an audit trail
We watch for suspicious activity Key actions — sign-ins, permission changes, exports, and record deletions — are logged, giving administrators visibility into who did what and when, and supporting investigations if something looks wrong.
We watch for suspicious activity
Our systems monitor for unusual sign-in patterns and account activity around the clock. When we identify suspicious behavior, such as repeated failed logins or access from an unrecognized location, we may flag or block the activity and, where appropriate, notify affected account administrators.
Your data is backed up
We take regular, encrypted backups of Platform data and maintain a disaster recovery plan so that, in the event of a system failure, your leads, projects, and tickets can be restored with minimal disruption.
Secure infrastructure
The Platform runs on reputable cloud infrastructure with physical, network, and environmental safeguards, and we apply security patches and updates on an ongoing basis to keep the underlying systems current.
Always advancing our security
As threats evolve, so do our practices. We regularly review and test our security controls, and we welcome reports from security researchers who identify potential vulnerabilities in good faith. To report a security concern, please email info@csquare.co with the subject line “Security Disclosure,” including enough detail for us to reproduce and assess the issue. We ask that you give us a reasonable opportunity to investigate and address any report before disclosing it publicly.
Keeping payment data safe
If you pay for your subscription by card, your payment details are collected and processed directly by our PCI DSS–compliant payment processor. C Square does not store your full card number on the Platform.
Questions?
If you have questions about our security practices, or need to report a concern, contact us at info@csquare.co.