Morfyncby Enterocity

Security

Separation, roles, and access built into the architecture.

Morfync is designed so that each client's data stays inside its own workspace and each user only reaches what their role allows.

Controls in place

How Morfync protects workspace data

Workspace separation

Morfync is multi-tenant. Each client operates in its own workspace with its own users, records, configuration, and access rules. Data access is scoped to the workspace a user belongs to.

Role-based access

Users are assigned roles within their workspace, and roles determine what can be viewed and changed. Roles are stored and enforced server-side, not in the browser.

Protected routes

Application areas require an authenticated session. Requests are authorised on the server for every protected operation, not only hidden in the interface.

Authentication

Accounts sign in through the Morfync application at app.morfync.com. Credentials are never stored in plain text and sessions are managed by the authentication layer.

Managed infrastructure

Morfync runs on managed cloud infrastructure with encrypted transport (HTTPS/TLS) between clients and the application, and managed database services with encryption at rest.

Activity trail

Records carry an activity history, so changes and interactions on a relationship remain visible to authorised users in the workspace.

Shared responsibility

Where our responsibility ends and yours begins

Security in a CRM is a partnership. This page is maintained by Enterocity to answer common security questions about Morfync; it is not an independent audit or certification.

Enterocity is responsible for

  • Building and operating the Morfync application and its access controls
  • Applying updates and fixes to the shared product
  • Configuring workspace separation and roles as agreed with each client
  • Responding to security questions and reported issues

Your team is responsible for

  • Deciding who is invited into your workspace and with which role
  • Removing access when someone leaves your organisation
  • Keeping account credentials confidential and unique
  • Deciding what data your team chooses to store in the CRM

What we do not claim

Morfync is an early-stage product operated by Enterocity, and we would rather be precise than impressive.

  • We do not currently hold SOC 2, ISO 27001, HIPAA, or PCI certification, and we do not describe Morfync as certified.
  • We do not use terms such as “bank-grade” or “unbreachable”. No system can guarantee that.
  • Data-processing terms and any regional requirements are agreed in writing with each client before a workspace goes live.

Reporting a security concern

If you believe you have found a vulnerability or a data issue in Morfync, contact Enterocity directly and give us the detail needed to reproduce it. We will acknowledge the report and keep you informed while we investigate.

Have a security review to complete?

Send us your questionnaire or your questions and we will answer them directly, including what is and is not in place today.