Data export and privacy
How data export works today, what's audited, and the honest state of data-residency and certification claims.
- Audience
- IT/security evaluators, Administrators, Owners & executives
- Permissions needed
- Export permission on the relevant module (separate from read access)
- Environment
- Production and staging
- Product version
- Current
- Last reviewed
- Owner
- Propulsive Product Team
Before you start
- We do not hold a third-party security certification (SOC 2, ISO 27001) or a formal contractual data-residency guarantee today - see Security & Compliance for the full, honest breakdown.
Exporting your data
Most list and report screens support export (typically CSV), gated by its own export permission separate from read access - so someone can view records without necessarily being able to pull a bulk export. Every export is written to the platform’s append-only audit log with the actor, what was exported, and when.
Deployment model and data separation
Each customer runs a dedicated, single-tenant deployment rather than sharing a database with other customers. Data separation comes from deployment architecture, not from row-level tenant filtering inside a shared database - there’s no cross-customer data store to leak from in the first place.
What we are not claiming
We’d rather state this plainly than let a badge or a vague phrase imply otherwise:
- No third-party security certification yet (SOC 2, ISO 27001 or similar) has been completed.
- No formal, contractual data-residency commitment per region is in place today.
- Independently rehearsed backup/restore drills are not something we can currently confirm as a mature, proven, repeatable practice - see Deployment & Onboarding.
If any of these are a hard requirement for your evaluation, ask us directly for current status and timeline rather than assuming from general ERP-market expectations.
Record retention and deletion
Core business records (contacts, companies, employees, vendors, items, accounts, transactions) are protected against casual hard-deletion - the default handling for records you no longer need is deactivation, archiving or merging, not permanent removal, unless you explicitly request deletion of specific records through your administrator.