Psalm/Security

Security and privacy

Your customers trusted you. We know what that means

A CRM holds the names, numbers and buying history of every person your business deals with. If you are handing that to us, you are entitled to know exactly where it goes, who can reach it, and what we will never do with it. Here is all of it, in plain English.

Where it lives

In London, and it stays there

Your database, your uploaded files and the application itself run in the United Kingdom. That is a choice, not a default that happened to us: it keeps your records under UK data protection law, in a country the EU recognises as offering adequate protection, and it means the answer to "where is my data" is a place rather than a shrug.

A handful of specialist suppliers sit outside the UK, and we name every one of them further down this page. Where personal data reaches them it travels under the UK International Data Transfer Addendum or Standard Contractual Clauses.

The one that matters most

Companies are kept apart by the database, not by our code

Most software keeps one customer's records away from another's with a check written in the application: a line that says "only show rows belonging to this company". It works right up until somebody forgets to write it on a new screen, and then it fails silently, and nobody finds out until the wrong person sees the wrong invoice.

Psalm does it a layer lower. Every table holding your information carries a rule enforced by the database itself, so a query that forgot to ask for your company gets nothing back rather than everything. There is no code path that can skip it, because it is not code. Every change that touches the database replays that protection against a fresh database and runs a suite of tests that deliberately tries to read across the boundary. If those fail, the change does not go out.

The practical protections

What is locked, and how

Encrypted coming and going

Every connection is TLS only. The database and your uploaded files are encrypted on disk. Passwords are never stored in a form anyone can read, including us: if you forget yours we can help you set a new one, and that is all we can do, which is exactly how it should be.

Backups your own supplier cannot read

Your data is backed up nightly and the backup is encrypted with a key our build system does not hold. It can lock the file and can never open it. Somebody who compromised our source control, our hosting and our whole GitHub account would come away with an unreadable file. The backups expire after 90 days.

Least privilege inside your company

Your team sees what their role and permissions allow, and nothing more. A salesperson's pipeline is private to them. Sensitive credentials sit in storage the application itself is not allowed to read, so a bug in a screen cannot reach them.

Watched

Errors across the whole service are recorded and grouped by fault, so a new problem is visible rather than buried in noise, and anything on the payment path is kept separately because money errors must outlive an ordinary log. Sign-in is rate limited and protected against automated attacks.

It works when the internet does not

Psalm keeps a copy of your working data on your own device so the app keeps going on a bad signal or no signal. That copy is cleared the moment you sign out, and a shared device does not keep the last person's records.

Every change is checked

Every change runs type checks, six hundred automated tests and a full production build before it ships. Any change touching the database additionally replays every migration against a clean database and runs eight suites that try to read across the boundary between companies.

Just as important

What we do not do

We do not sell your data. We do not share it for anyone's advertising. We do not use your business records to train AI models, ours or anybody else's. We do not read your workspace out of curiosity: we look at your records when you ask us to, because you have raised a problem with a specific one.

There are no advertising cookies, no analytics trackers and no third-party pixels on this website or in the app. We do not follow you around the internet and we do not build a profile of you. That is also why you have never seen a cookie banner from us. We have nothing to ask your permission for.

The assistant

AI that is on a short lead, and has an off switch

Psalm includes an assistant that answers questions about your own figures, checks wording, drafts a quotation and writes a summary. It runs on our account with Anthropic, so you never supply a key of your own. Only what a task actually needs is sent: a grammar check sends the sentence you are writing, not your database. Nothing you keep in Psalm is used to train a model.

What it is allowed to do is fixed in advance. It can change a setting only from a list held in our database, and only when a company owner asks. It cannot write database queries, reach another company's workspace, alter a financial figure, use up an invoice number, or send anything at all to your customers. When it suggests a change to something you wrote, it shows you and waits.

And if you would rather have none of it, a company owner can switch the assistant off for everyone in Settings. With it off, nothing from your workspace goes to a model. The daily summary is a separate switch and starts off until you turn it on. More about the assistant.

Yours, and provably so

Take it with you, or have it destroyed

Plenty of software promises this in a policy and makes you email support to find out it was never built. In Psalm both are buttons, in Settings, and a company owner can press them without asking us.

Export everything gives you a spreadsheet of your company's records: contacts, leads, quotations, orders, invoices, payments, purchases, stock, projects, people, letters, drafts and your billing history, one sheet each. No notice period, no fee, no conversation with a retentions team. Uploaded files are not in the spreadsheet, so download anything you still need from the records themselves. Private to-dos and reminders belonging to your staff are theirs, not the company's, so an owner's export contains only their own.

Delete this company removes every record, file and login belonging to it, immediately. Encrypted backups roll off within 90 days and then it is gone from those too. We ask you to type your company name first, because it cannot be undone and we cannot get it back for you.

No mystery third parties

Everyone who touches your data

The list is short on purpose, and every one of them is under a written contract to process data only on our instructions.

  • Supabase (United Kingdom, London): the database, sign-in and file storage that hold your workspace.
  • Vercel (United Kingdom, London): hosting and delivering the application.
  • Anthropic (United States): the AI model behind the assistant, used only when you use it, and never for training.
  • Stripe (United States and Ireland): subscription payments. Card details go to them directly and never reach us.
  • Resend (United States): delivering the emails you send from Psalm, and our own service emails.
  • Cloudflare (global network): protecting the sign-in pages from automated attacks.
  • GitHub (United States): storing the nightly encrypted backups, which they cannot read.

One more, for completeness, though it never sees anything you keep in Psalm: this marketing website loads its typefaces from Google Fonts, which means Google sees the address of a browser visiting these pages. The application itself serves its fonts from our own servers, so signing in tells Google nothing.

If we ever add or replace a supplier, this page and the privacy policy change before the supplier does.

Honesty about the bad day

If something goes wrong

No system is perfectly secure and anyone who tells you otherwise is selling something. What we can promise is how we would behave.

If a breach affects personal data and is likely to put anyone at risk, we report it to the Information Commissioner's Office within 72 hours of finding out, and we tell the people affected without delay where the risk to them is high. If you are a customer, we tell you promptly and in enough detail for you to meet your own obligations, well inside your own 72-hour clock. We would rather tell you something awkward early than something tidy late.

If you have found a security problem in Psalm, please write to info@psalmcrm.com and say so in the subject line. We will reply, we will fix it, and we will not come after you for telling us.

Where we are not yet

What we are not claiming

Psalm does not hold ISO 27001 or a SOC 2 report. Those audits cost tens of thousands of pounds and mostly certify that a large company has written its procedures down. We would rather put that money into the product until a customer genuinely needs the certificate, and we would rather say so here than let you assume.

What you get instead is this page, a data processing agreement that is already in force without you having to ask for it, and a straight answer to any security question you send us. If your procurement process needs a questionnaire completed or the agreement signed on your own paper, say so and we will do it.

Read the rest of it in full

The policies are short, written in English, and say the same things this page does.