Security you can show, not just claim.
CentralContacts is built so that doing the right thing is the default — from how we store a password to how we record a reason on every contact. Here's exactly how your data is protected.
How your data is protected
Defence in depth — from the database up to the reason on record.
Secure authentication
Passwords are hashed with bcrypt and never stored in plain text. Sessions use secure tokens with automatic expiry, and resets go through email verification.
Row-level security
Row-level security on the tables holding customer data means every query is filtered at the database — users only ever see data they're authorised to see.
Role-based access
Distinct Admin, Employee and Super-Admin roles with least-privilege permissions and audit logging, so the right people have the right access.
Organisation isolation
A multi-tenant architecture keeps every organisation's data fully separated. Your directory is never visible to another company.
Encrypted & UK/EU hosted
Data is encrypted in transit and at rest, hosted in the UK/EU. A purpose, a lawful basis and an audit trail sit on every contact by design.
The reason on record
Every contact carries a purpose, a lawful basis and a timestamp — so 'why do you hold this?' always has a written answer.
The person always keeps control.
Data-subject rights aren't a support ticket here — they're features. The person a contact is about can see, correct and control their record, and you can honour a request in a click.
- ✓ Export the whole directory, anytime — no lock-in
- ✓ Rectify details through the contact's own portal
- ✓ Erase on request — soft-delete with an audit line, never a silent purge
- ✓ Positive-only verification — a badge reassures, it never accuses
A directory your team — and your DPO — can trust.
A reason on record for every contact, security you can show, and your data exportable anytime.