Zoho CRM and Security: A partnership that forms the bedrock of our operations

Zoho CRM and Security: A partnership that forms the bedrock of our operations

In August 2025, a leading human resources and financial management software provider, Workday, fell prey to a social engineering attack targeting a third-party customer relationship management (CRM) system. The incident exposed the company's business contact information, including names, emails, and phone numbers.

 

The same month, 2.5 million of Google's customer data records were compromised in a similar attack on its CRM system. One of the powerful IT companies in the world was victim to a voice phishing event that led to this incident.

 

Around that time, Farmer's Insurance, a leading US-based insurance company, was also suffered an attack which affected 1.1 million members of its customer base. The company confirmed in a statement that unauthorized actors gained access to a third-party database that contained sensitive customer information.

 

These are all different companies, from different regions and different sectors, catering to widely varied customer bases—yet they all have one thing in common: In each case, their CRM provided a gateway for malicious actors to gain entry to their sensitive systems, offload millions of records, and hold them for ransom.

Security and Zoho CRM 

Security is built into our DNA. While we take steps to improve product functionalities continually and keep up with the dynamically evolving needs of our customers, we make sure that every build shipped, every feature released, and every new change is built with security at its core—including Zoho CRM.

 

Our product's architecture is built with a security-first approach, which means that our customers can trust us to keep their data secure and protected but available for effortless business use.
 
At its foundation, Zoho CRM is protected by several layers of security—an approach which eliminates any risks to your data with preventive controls, continuous monitoring, and strict access governance.

 

At the infrastructure level, Zoho CRM operates on secure, globally distributed data centers with strong physical and network protection. Data is protected at rest and in transit to safeguard customers' sensitive data during operations. Regular security audits, vulnerability assessments, and compliance with global standards ensure that Zoho CRM's platform remains secure and reliable, making it ideal for enterprises and businesses for all sizes. Zoho complies with global standards such as SOC 2, ISO 27001, and several industry-specific certifications.

 

 

At the product level, Zoho's multi-tenant architecture emphasizes granular access controls, authentication, and traceability to keep its data secure. Role-based access, profile-based permissions, and field-level access restrictions, along with secure data-sharing rules, all ensure that users can only perform the operations (viewing, creating, editing, or deleting records) they're authorized to perform at the module- and field-level. Every action performed in the Zoho CRM system is logged for usage monitoring and anomaly detection through detailed audit trails. This enables organizations to enforce security while maintaining organizational policies.

Security: A shared responsibility between Zoho and its customers 

As a vendor, Zoho takes utmost care to keep your data safe and secure, but security is a shared responsibility between the vendor and its customers. Particularly in the face of advanced threat attacks like phishing, sophisticated social engineering, ransomware, and malware attacks.

Threat actors employ a multitude of tactics to gain entry into their target systems and usually deploy an array of attack tactics. In the examples described, voice phishing—where threat actors call on some of the organization's CRM users pretending to be an IT assistant—was used to get users to perform actions that could compromise its data security. Another popular tactic is to get users to connect unauthorized applications or plug malware into their CRM systems, which would then siphon off data from the CRM system in small packages.

 

Such attacks call for joint action plans between us, the vendors, and you, as customers, to secure your data from attacks and threats. Below are some of the key security features and best practices that organizations can adopt at the user end to ensure complete data security.

Tighten access to your CRM with multi factor authentication (MFA) 

Credential stuffing and password spraying account for the most prevalent automated cyberattacks, driven in part by frequent re-use of passwords and the use of weak authentication protocols. Individual password attacks and success rates are comfortingly low, at about 0.1% to 2%. However, given the larger scale of attacks that bots can facilitate, those success rates can hit as high as 40%, as stated in this article.

 

A simple yet effective way to guard your data against credential-related attacks is to secure them with multi-factor authentication with time-based one-time passwords (TOTP). Besides using strong passwords and never re-using passwords, MFA provides an additional layer of security to your data. Zoho offers OAuth support with its own application called Zoho OneAuth. Access via APIs is also secured via OAuth-based authentication mechanisms to secure your data. Zoho also supports single sign-on (SSO) using industry standards like SAML, if you're part of the ecosystem of Zoho apps.

 

In sales, external partners, third-parties, or vendors often need access to select pieces of information in your CRM. Zoho CRM offers secure client portals whereby external users—who aren't part of your organization—can securely access your system via authentication mechanisms such as OAuth and SSO.
 

Follow the principle of least privilege: Grant users access only to the data they need 

A newly-joined sales rep doesn't have to access details of high-value deals in their first week on the job. The sales manager of one region—say, APAC—doesn't need access to customer history from another region. Enforce strong access controls and make sure users only have access to the data that they need to complete their tasks. Anything more than this compromises your data security and exposes sensitive data to unforeseen threats; anything less hinders productivity and forces your agents to run to others to gain access to data that they need to fulfill their jobs.

 

Zoho CRM offers profile-based and role-based access controls—the RBAC model—to ensure your data stays secure. Role-based user permissions limit access to users associated with roles such as sales reps, area manager branch managers, VPs, directors, and CEOs. Granular permission levels also define whether users can see their peers' data.
 
Use profile-based permissions to limit users' access to specific modules. That is, choose and limit what users can do in each module, like create, view, edit, or delete records. Zoho CRMs profile-based permissions help you avoid giving free reins to every single CRM user, while also ensuring they have access and permissions to carry out their activities without impeding productivity.

 

Zoho CRM's access permissions also offer field-level permissions where you can determine if users associated with a specific profile can access—create, edit, view or delete—specific fields in any module in the CRM. For example, if you have your customers' credit card information in your Leads module, you can mask that field so that CRM users (your sales agents) won't have access to that field.

Impose IP-based restrictions to prevent unauthorized access 

When you restrict access to your applications to a range of IPs, you automatically end up securing your systems against unauthorized access and phishing attempts. Field sales agents connecting from other countries or other networks can secure their connections by using a VPN to access CRM. This ensure total security and protects you against unverified and untrusted IP accesses. You can implement an additional step, wherein systems connecting from unknown IPs are challenged to verify their identities and authenticate their access, as an additional security layer. 

Track user activity with audit logs 

Despite stringent access controls and protocols in place to keep your data safe, you might want to keep a trail of all activities performed in your CRM application. Zoho CRM enables you to do just that with audit logs, which is a detailed, time-stamped event history of all actions—user-performed activities, administrative actions, and key system events—performed in the application in chronological order. You can track record creation, record modification, approval submissions, workflows creation, and bulk activities such as mass record updates, deletions, and exports.

 

For easy access, users can filter out audit logs by actions performed. This way, users can filter entries in audit log based on the module, user, action type, or a selected date range.
 
Audit logs are accessible to all users. However, each user will only be able to view their own audit trail and not the audit logs of other uses. Admin users will have complete access audit logs, along with options to export them. Audit logs in Zoho CRM are maintained for up to three years.

Secure by design: Tenant isolation in Zoho CRM 

When we say privacy and security are built into Zoho's core, that means that when you rely on our cloud infrastructure, our robust model ensures that infrastructure is shared for efficiency, while your data remains secure.

 

In Zoho CRM, tenant isolation is a core part of our security operations. The platform operates on a multi-tenant model with strict logical data isolation to ensure that each organization's data remains securely segregated. Even within a shared database infrastructure, access is governed through our sharing model, so one tenant's data is completely isolated and inaccessible to others. This approach enables businesses to scale efficiently while maintaining strong data privacy and security boundaries.

Zoho CRM: Certification and independent audits 

Zoho CRM maintains industry-recoginized certifications including ISO/IEC 27001, ISO/IEC 27017, and ISO/IEC 27018, and we undergo SOC 2 Type II independent audits. These certifications validate Zoho's cloud security controls and information security management, and ensures protection of personally identifiable information (PII).

 

Zoho also complies with global privacy regulations such as GDPR and industry-specific regulations like HIPAA. Zoho is subject to periodic external audit from certified audit bodies and third parties that assess and validate our security and privacy posture.

Zoho CRM: Security you can trust 

In Zoho CRM, security isn't an afterthought, it's a layer that is embedded across the CRM platform. From access controls to monitoring and compliance readiness, Zoho CRM is designed to protect your data at every step without compromising usability. As organizations scale and grow, this security-first approach ensures that teams can operate with confidence that their data is safe, governed, and always under their control.

 


        Create. Review. Publish.

        Write, edit, collaborate on, and publish documents to different content management platforms.

        Get Started Now


          Access your files securely from anywhere

            Zoho CRM Training Programs

            Learn how to use the best tools for sales force automation and better customer engagement from Zoho's implementation specialists.

            Zoho CRM Training
              Redefine the way you work
              with Zoho Workplace

                Zoho DataPrep Personalized Demo

                If you'd like a personalized walk-through of our data preparation tool, please request a demo and we'll be happy to show you how to get the best out of Zoho DataPrep.

                Zoho CRM Training

                  Create, share, and deliver

                  beautiful slides from anywhere.

                  Get Started Now


                    Zoho Sign now offers specialized one-on-one training for both administrators and developers.

                    BOOK A SESSION







                                Quick LinksWorkflow AutomationData Collection
                                Web FormsEnterpriseOnline Data Collection Tool
                                Embeddable FormsBankingBegin Data Collection
                                Interactive FormsWorkplaceData Collection App
                                CRM FormsCustomer ServiceAccessible Forms
                                Digital FormsMarketingForms for Small Business
                                HTML FormsEducationForms for Enterprise
                                Contact FormsE-commerceForms for any business
                                Lead Generation FormsHealthcareForms for Startups
                                Wordpress FormsCustomer onboardingForms for Small Business
                                No Code FormsConstructionRSVP tool for holidays
                                Free FormsTravelFeatures for Order Forms
                                Prefill FormsNon-Profit

                                Intake FormsLegal
                                Mobile App
                                Form DesignerHR
                                Mobile Forms
                                Card FormsFoodOffline Forms
                                Assign FormsPhotographyMobile Forms Features
                                Translate FormsReal EstateKiosk in Mobile Forms
                                Electronic Forms
                                Drag & drop form builder

                                Notification Emails for FormsAlternativesSecurity & Compliance
                                Holiday FormsGoogle Forms alternative GDPR
                                Form to PDFJotform alternativeHIPAA Forms
                                Email FormsFormstack alternativeEncrypted Forms

                                Wufoo alternativeSecure Forms

                                TypeformWCAG


                                    All-in-one knowledge management and training platform for your employees and customers.

                                              Create. Review. Publish.

                                              Write, edit, collaborate on, and publish documents to different content management platforms.

                                              Get Started Now




                                                                You are currently viewing the help pages of Qntrl’s earlier version. Click here to view our latest version—Qntrl 3.0's help articles.




                                                                    Manage your brands on social media


                                                                      • Desk Community Learning Series


                                                                      • Digest


                                                                      • Functions


                                                                      • Meetups


                                                                      • Kbase


                                                                      • Resources


                                                                      • Glossary


                                                                      • Desk Marketplace


                                                                      • MVP Corner


                                                                      • Word of the Day


                                                                      • Ask the Experts


                                                                        Zoho Sheet Resources

                                                                         

                                                                            Zoho Forms Resources


                                                                              Secure your business
                                                                              communication with Zoho Mail


                                                                              Mail on the move with
                                                                              Zoho Mail mobile application

                                                                                Stay on top of your schedule
                                                                                at all times


                                                                                Carry your calendar with you
                                                                                Anytime, anywhere




                                                                                      Zoho Sign Resources

                                                                                        Sign, Paperless!

                                                                                        Sign and send business documents on the go!

                                                                                        Get Started Now




                                                                                                Zoho TeamInbox Resources





                                                                                                          Zoho DataPrep Demo

                                                                                                          Get a personalized demo or POC

                                                                                                          REGISTER NOW


                                                                                                            Design. Discuss. Deliver.

                                                                                                            Create visually engaging stories with Zoho Show.

                                                                                                            Get Started Now








                                                                                                                                • Related Articles

                                                                                                                                • Zoho CRM's Core Data Model and How You Extend It Safely

                                                                                                                                  Zoho CRM ships with a complete set of standard modules covering every stage of the sales cycle, and gives your team structured, governed ways to extend that model as your business grows. Here is how the core data model is built, what it covers, and ...
                                                                                                                                • Working with Zoho Forms Integration

                                                                                                                                  What are Zoho Forms? Using Zoho Forms, you can easily build an online form for all your business needs. Create and customize the form, add the required fields and send it to your customers thus facilitating data collection. It allows you to capture ...
                                                                                                                                • Data Encryption in Zoho CRM

                                                                                                                                  Encryption is primarily used to safeguard the contents of a message so that only the intended recipient can read it. This is done by replacing the contents with unrecognizable data, which could be understood only by the intended and authorized ...
                                                                                                                                • How Zoho CRM Administration and Configuration Works for Sales Operations

                                                                                                                                  Zoho CRM gives sales operations teams a full stack of admin tools covering workflow automation, lead routing, UI customisation, permissions, and change management, all accessible without needing a development team. Here is how each layer works, ...
                                                                                                                                • Contact roles support for deals in Zoho CRM iOS app

                                                                                                                                  You can now assign specific roles to the contacts involved in a deal, making it easier to manage your sales process. When you're managing a deal, there may be several key people from the prospective company involved- like decision-makers, financial ...
                                                                                                                                  Wherever you are is as good as
                                                                                                                                  your workplace

                                                                                                                                    Resources

                                                                                                                                    Videos

                                                                                                                                    Watch comprehensive videos on features and other important topics that will help you master Zoho CRM.



                                                                                                                                    eBooks

                                                                                                                                    Download free eBooks and access a range of topics to get deeper insight on successfully using Zoho CRM.



                                                                                                                                    Webinars

                                                                                                                                    Sign up for our webinars and learn the Zoho CRM basics, from customization to sales force automation and more.



                                                                                                                                    CRM Tips

                                                                                                                                    Make the most of Zoho CRM with these useful tips.



                                                                                                                                      Zoho Show Resources