1. Executive Summary
scornm is built from the ground up on a strict Zero-Trust and Zero-Knowledge philosophy. Unlike traditional legacy CRMs where customer records and communication transcripts sit unencrypted in monolithic shared databases accessible by vendor engineers, scornm enforces cryptographic isolation across all data planes.
This document outlines the operational mechanisms, cryptographic standards, network boundaries, and disaster recovery procedures engineered into the scornm platform.
2. Zero-Knowledge EKM (Bring Your Own Key)
Enterprise customers on the Elite tier maintain 100% sovereign ownership over their data encryption keys using Enterprise Key Management (EKM / BYOK).
Envelope Encryption Architecture
Data at rest is secured via two-tier AES-256-GCM Envelope Encryption:
- Data Encryption Keys (DEK): Generated per customer tenant using cryptographically secure pseudorandom number generators (random_bytes(32)).
- Key Encryption Key (KEK / Master Key): Your external Customer Master Key (CMK) hosted in AWS KMS, Azure Key Vault, or a dedicated Hardware Security Module (HSM).
Revocation Guarantee: If you disable or delete your KMS Key ARN in your AWS/Azure cloud console, all tenant data within scornm becomes mathematically unreadable immediately, ensuring complete zero-knowledge privacy.
3. Application-Layer Encryption (ALE)
Unlike standard disk-level Transparent Data Encryption (TDE) where database processes and DBAs can view plaintext values in SQL memory, scornm performs in-memory Application-Layer Encryption (ALE) before data touches the database engine.
- Field-Level Cryptographic Isolation: Personally Identifiable Information (PII), lead contact details, financial numbers, WhatsApp logs, and private notes are encrypted in the application layer using authenticated AES-256-GCM with unique Initialization Vectors (IVs) per field.
- DBA Zero-Knowledge: Even with full physical database dumps or compromised SQL replication logs, raw data appears exclusively as cryptographically sealed base64 payloads (iv:tag:ciphertext).
4. True End-to-End Encryption (E2EE) & VLE
For internal messaging, audio notes, and real-time collaboration:
- Per-Device Client Keys (E2EE): Keys are derived on user devices via the standard WebCrypto API (ECDH P-256 + AES-GCM-256). Messages and attachments are encrypted in the browser/app before reaching the wire.
- Voice & Video Live Encryption (VLE): Team audio and video calls operate over peer-to-peer WebRTC channels secured with DTLS-SRTP. Media streams flow encrypted point-to-point without server-side packet decoding or recording intercept.
5. Enterprise Identity & Access Governance (IAM)
scornm natively implements standards-compliant enterprise identity federation:
- SAML 2.0 Single Sign-On: Supports all major identity providers (Okta, Microsoft Entra ID / Azure AD, Google Workspace, PingIdentity). Supports corporate email domain routing, SHA-256 assertion signature validation, and optional Just-In-Time (JIT) user auto-provisioning.
- SCIM 2.0 Directory Synchronization (RFC 7643 / RFC 7644): Inbound RESTful endpoints (/api/scim/v2/Users) allowing corporate IT to automatically provision new hires and instantly deprovision departed employees in real time upon IdP directory update.
- Hardware Passkeys & WebAuthn: FIDO2-compliant biometric authentication (Fingerprint, Touch ID, Face ID, YubiKey) providing complete immunity to phishing and credential stuffing attacks.
6. Network Boundary & Team IP Allowlisting
To prevent credential abuse outside corporate premises:
- CIDR Subnet Enforcement: Super Admins can restrict team login to corporate static office IPs or corporate VPN subnets (e.g. 192.168.1.0/24, 10.0.0.0/8, or static IPv4/IPv6 addresses).
- Reverse Proxy & DDoS Shield: Enforced TLS 1.3 encryption, automatic rate-limiting against brute force, and strict Origin/Referer verification on all state-changing endpoints.
- Zero SQL Injection Surface: All database transactions execute exclusively through parameterized PDO prepared statements.
7. Database Multi-Tenancy & Isolation
Every database entity (leads, pipelines, tasks, follow-ups, documents) is tagged with an immutable team_id and super_admin_id identifier.
Our session security engine strictly verifies that the authenticated user's active tenant scope matches the requested resource ID on every single read/write request. Cross-tenant leakage is strictly impossible at the query resolution level.
9. Compliance Posture & SLA Guarantees
scornm's controls are aligned with international security and data protection benchmarks:
SOC2 Type II Aligned
Security, Availability & Confidentiality Trust Principles
GDPR & DPDP Compliant
Right to access, data portability & right to erasure
99.99% Uptime SLA
Financially backed uptime guarantee for Elite accounts
Responsible Disclosure
Security incident response and vulnerability bounty program