Security
CallNexaCRM is designed around role-based access and separation of Admin-panel data.
Access controls
- Separate roles for Super Admin, Admin, Team Leader and Employee.
- Authenticated sessions are required for CRM APIs.
- Admin-panel data is scoped by tenant where applicable.
- Password reset invalidates the affected user's existing sessions.
Payment secrets
Gateway secrets must remain server-side and should never be embedded into browser JavaScript or public pages. Production deployments should store secrets in protected environment variables or a dedicated secret manager.
Production deployment
Use HTTPS, a production database, encrypted backups, secure headers, rate limiting, log monitoring, strict CORS rules where applicable and regular dependency/security updates before exposing the service publicly.