Built to be trusted with
a builder’s customer database.
One database per workspace, two-factor and passkeys, encryption at rest, an append-only audit trail, and a DPDP Act 2023 processor posture with a published data processing agreement.
Your buyers’ data, in your own database.
One database per workspace. Provisioned, exported or deleted on its own.
Two-factor and passkeys
Authenticator app with recovery codes, enforceable per workspace. Passkeys for fingerprint or face sign-in. Sessions visible and revocable; account lockout; rate limits.
Encryption at rest
AES-256-GCM for sensitive personal fields — Aadhaar, PAN, addresses, payment references. TLS in transit. A strict content-security policy on every page.
Append-only audit trail
Every state change is attributed to a user and kept. Management can read it; nobody can edit it.
DPDP Act 2023 posture
Your business is the Data Fiduciary; ZevroCRM is the Processor. A data processing agreement listing sub-processors is published, and workspace data is exportable and deletable.
Scheduled backups. A full security review and hardening pass was completed in August 2026.
Proven in production
In daily use at a Chennai residential builder since July 2026 — real quotes, real bookings.
- Multi-tenant platform live since August 2026: one Postgres database per workspace and a super-admin console for provisioning, plans, modules, usage and support.
- CI with a dependency-vulnerability gate; a deploy script with verification and rollback; scheduled backups.
- WhatsApp staff alerts delivered to real handsets in production; Meta business verification complete.
- Security review and hardening pass, August 2026.
Made in Chennai by Ethereal Design Studio. Indian defaults everywhere: ₹, lakh and crore, DD-MM-YYYY, IST, RERA, DLT, GST and TDS.
Where your data sits,
and who can reach it.
What an IT administrator or a compliance reviewer asks before sign-off.
How is our customer data kept separate from other companies?
Every ZevroCRM workspace gets its own database, rather than sharing one table with a tenant column. That means one company’s buyer records are not stored alongside another’s, and a workspace can be exported or deleted on its own.
What security controls does ZevroCRM have?
ZevroCRM supports enforced two-factor authentication and passkeys, so staff can sign in with a fingerprint or face instead of a shared password. Every change is attributed to a user in an audit trail, and each workspace is isolated in its own database.
Where does our data sit under India’s DPDP Act?
Under the Digital Personal Data Protection Act, 2023, the subscribing business remains the Data Fiduciary for the buyer data in its ZevroCRM workspace and ZevroCRM acts as its Processor. A data processing agreement listing our sub-processors is available at /legal/dpa/.
What happens to our data if we stop using ZevroCRM?
Your workspace data stays exportable and deletable for as long as the workspace exists. On exit we confirm the export and deletion steps with your named administrator rather than deleting anything on our own schedule.
Can ZevroCRM run on our own brand and domain?
Yes. ZevroCRM is white-label: an enterprise workspace can run on your own domain with your branding, and use your own WhatsApp and SMS sender IDs. Registering your own senders typically takes around two weeks, so shared senders are used until then.
Privacy policy · Still unsure whether it fits how you sell? Book a demo or write to hello@zevrocrm.com.
Let’s talk about
your property sales.
Tell us a little about your team and projects. We’ll show you exactly how ZevroCRM fits your sales workflow — from first enquiry to final booking.
- A 30-minute personalised walkthrough
- See it set up with your own projects
- Guidance on moving off spreadsheets
- No obligation — we reply within a day