Skip to content
KudosCRM

Founding offer: we set up your CRM for you — free for the first 100 teams. Book your setup

Help · Admin, account and security

Change your password and secure your account

The account security you control yourself, what protects your data at the platform level, and an honest account of which enterprise controls are available and on which tier.

Updated August 2026

Account security has three layers: what you do, what your admin does, and what the platform does. This covers all three, including where the limits are.

Who this is for

Every user for the first part; admins and anyone doing a security review for the rest.

Before you start

  • Access to your own account settings.
  • For the admin sections, permission to manage users and view audit logs.

What we claim, and what we do not
Concretely available today: tenant isolation at the data layer, role-based access control, a full audit log, and encryption in transit. Single sign-on and SCIM provisioning are Enterprise-tier features. We do not claim SOC 2 or ISO 27001 certification — if a certification matters to your procurement process, ask rather than assume.

Secure your account

  1. Use a strong, unique password
    Change it from your account settings. Unique matters more than complex — a password reused from a breached site is the most common way accounts are lost.
  2. Use a password manager
    It is the only realistic way to have a genuinely different password everywhere, and it costs you nothing after setup.
  3. Give people the right role
    Access is granted by role rather than per person. The narrowest role that lets someone work is the correct one — this is the control with the largest practical effect.
  4. Remove access when people leave
    The most common real-world security gap is not an attack; it is an account that was never removed.
  5. Review the audit log periodically
    It records who did what across your records and key settings, and it cannot be edited from the app.
  6. Consider SSO if you are on Enterprise
    Single sign-on means people authenticate through your existing identity provider, and SCIM keeps accounts in sync as people join and leave. Both are Enterprise-tier.

What you get

  • An account credential you control and can change.
  • Access bounded by role rather than granted wholesale.
  • An unalterable record of who changed what.
  • A clear, honest picture of which controls exist and on which tier.

Frequently asked questions

Do you support SSO and SCIM?

Yes, on the Enterprise tier. SSO lets your team sign in through your existing identity provider; SCIM keeps accounts in sync with your directory as people join and leave.

Are you SOC 2 or ISO 27001 certified?

We do not claim certifications we do not hold. What is concrete today is tenant isolation at the data layer, role-based access control, a full audit log and encryption in transit. Ask us directly if a certification is a procurement requirement.

How is my data kept separate from other customers?

KudosCRM is multi-tenant with row-level isolation — every record is tied to your account and every read is scoped to it at the data layer, not merely hidden in the interface.

What is the highest-impact thing an admin can do?

Give people the narrowest role that lets them work, and remove access promptly when they leave. Those two do more in practice than any other setting.

Related articles

Have an account issue this guide doesn't cover?

Open a ticket Track your requests

Start free today

Ready to give your team a CRM they'll actually use?

Start free. Bring your whole team. Cancel whenever (you won't).