How Cimplify protects your data
Charities hold highly sensitive information about supporters, volunteers, staff and, in many cases, the people they support. It is therefore essential that CRM systems are designed and managed with security in mind.
Cimplify is built entirely on the Salesforce platform. Goodlabs configures and supports Cimplify for customers, but does not operate a separate database or hosting environment containing customer data.
Your data is held in your own Salesforce environment
Each Cimplify customer has its own Salesforce organisation, with its own users, permissions and access controls.
This means there is no central Goodlabs database containing the combined information of all Cimplify customers, and there is no single Goodlabs login or access key that provides access to every customer's system.
Access to one customer's Salesforce environment does not automatically provide access to another customer's environment.
This separation is an important part of the way Cimplify is designed and helps to limit the potential impact of a compromised account or security incident.
Goodlabs does not store copies of your CRM data
Goodlabs does not routinely download or store copies of customer CRM databases on its own servers or devices.
Your live Cimplify data remains within Salesforce's cloud infrastructure.
Where Goodlabs needs to access customer data for support, development or maintenance, this is done directly within the relevant customer's Salesforce environment rather than by maintaining a separate Goodlabs copy of the database.
There may occasionally be circumstances where a customer provides Goodlabs with a data file for an agreed task, for example during an initial data migration or a specific data-cleaning exercise. Where this happens, the information is handled only for the purpose agreed with the customer and is not treated as a permanent Goodlabs copy of the CRM.
How Salesforce protects the underlying platform
Salesforce is responsible for the underlying cloud platform on which Cimplify operates.
Its security architecture includes measures such as encryption of data in transit and at rest, resilient cloud infrastructure, access controls, monitoring and security processes designed to protect customer environments.
Salesforce also operates extensive security, privacy and compliance programmes and publishes information about the security and availability of its services through Salesforce Trust.
Goodlabs does not attempt to replicate Salesforce's infrastructure security. Instead, Cimplify benefits from being built on a major enterprise cloud platform whose security controls are managed at a scale that would not be realistic for a small specialist CRM provider to reproduce independently.
Protecting administrative access
The accounts with the greatest level of access to a CRM also present the greatest potential risk if they are compromised.
For that reason, Goodlabs applies stronger authentication requirements to privileged Cimplify administrator accounts.
Goodlabs' own administrative access to customer environments is established separately for each customer and protected using phishing-resistant passkey authentication, including biometric authentication on authorised devices.
There is no master Goodlabs account that automatically opens every customer system.
User permissions and least privilege
Security is not only about preventing an external attacker from entering a system. It is also about making sure that users have no more access than they reasonably need to carry out their role.
Cimplify therefore uses Salesforce's permissions framework to control what individual users can see and what actions they can perform.
Goodlabs is continuing to strengthen the standard security configuration used across Cimplify customers. This includes reviewing whether ordinary users should routinely have capabilities such as:
exporting large volumes of information from reports;
accessing Salesforce through APIs or advanced technical tools;
viewing information outside the areas required for their role;
making large-scale changes to records.
Where these capabilities are genuinely required, they can still be provided to nominated users. The principle is that elevated access should be granted deliberately rather than simply being available by default.
Security is a shared responsibility
No technology platform can remove every possible security risk.
Salesforce is responsible for protecting the underlying platform and infrastructure. Goodlabs is responsible for designing, configuring and supporting Cimplify appropriately. Customers also play an important role by managing their own users and ensuring that access reflects people's current responsibilities.
Good practice includes removing accounts promptly when staff leave, reviewing administrator access, using strong authentication and limiting access to sensitive information wherever possible.
This shared approach helps reduce both the likelihood and the potential impact of an incident.
Our approach
Goodlabs' approach to security is based on a simple principle: reduce unnecessary access and reduce the potential impact if an individual account is ever compromised.
Using separately controlled Salesforce environments for each customer is an important part of that approach. So too are strong authentication, carefully managed permissions and avoiding the creation of unnecessary additional copies of customer data.
Security practices will continue to evolve as technology and threats change, and Goodlabs will continue to review the Cimplify security model and discuss appropriate improvements with customers.
For more detailed information about the security of the underlying Salesforce platform, customers can visit the Salesforce Trust website or ask Goodlabs for further information.