Security

CallNexaCRM is designed around role-based access and separation of Admin-panel data.

Access controls

  • Separate roles for Super Admin, Admin, Team Leader and Employee.
  • Authenticated sessions are required for CRM APIs.
  • Admin-panel data is scoped by tenant where applicable.
  • Password reset invalidates the affected user's existing sessions.

Payment secrets

Gateway secrets must remain server-side and should never be embedded into browser JavaScript or public pages. Production deployments should store secrets in protected environment variables or a dedicated secret manager.

Production deployment

Use HTTPS, a production database, encrypted backups, secure headers, rate limiting, log monitoring, strict CORS rules where applicable and regular dependency/security updates before exposing the service publicly.