Trust & Security
This page is maintained by Mars Financial LLC to answer common security and privacy questions about Astralscrm. It describes the controls that are enabled today and the responsibilities we share with our customers. It is not a certification, audit opinion, or legal guarantee.
Important disclaimer
Astralscrm is software, not a law firm, compliance consultant, or insurance advisor. It does not provide legal, regulatory, tax, or compliance advice. No feature guarantees compliance with any federal or state law, Department of Insurance regulation, NAIC model act, TCPA, DNC rule, or carrier requirement. Compliance obligations rest entirely with the subscribing agency and its licensed producers, who must independently verify the requirements for every state in which they operate. Astralscrm has not been certified under SOC 2, ISO 27001, HIPAA, or any similar framework.
Software only — no compliance, legal, or advisory services
- Astralscrm is software. Mars Financial LLC is not a law firm, compliance consultant, insurance advisor, carrier, IMO, or producer, and does not provide legal, regulatory, tax, or compliance advice.
- No feature guarantees compliance with any federal or state law, Department of Insurance regulation, NAIC model act, TCPA, DNC rule, or carrier requirement. Every feature is an aid you configure and supervise.
- Compliance obligations rest entirely with the subscribing agency and its licensed producers, who must independently verify the requirements for every state in which they operate.
- Nothing on this page is a warranty, certification, audit opinion, or legal guarantee.
Two capacities of Mars Financial LLC
- As platform operator, Mars Financial LLC supplies Astralscrm as software. Subscribing agencies remain responsible for their own licensure, their own client data, and their own regulatory obligations; Mars Financial LLC makes no determination about any of them.
- Separately, Mars Financial LLC is itself a licensed insurance agency — a resident Michigan business entity registered with NIPR, holding its own agency National Producer Number and naming a designated responsible licensed producer. In that capacity it is a customer of this platform and carries the same agency-level responsibilities as any other subscriber.
- Being a subscriber does not make Mars Financial LLC responsible for your agency's compliance, and Mars Financial LLC's own agency licensure is not a representation, endorsement, or certification regarding any other agency or the Service.
No third-party certification
- Astralscrm has not been certified, audited, attested, or accredited under SOC 2, ISO 27001, HIPAA, PCI DSS, or any similar framework.
- Nothing in the product, this page, or any marketing material should be read as claiming such a certification. If you see language that suggests otherwise, treat it as an error and tell us.
- Mars Financial LLC is not a HIPAA covered entity. Health-related answers collected during application intake are handled under the controls described on this page, not under a certified framework.
Reference data changes and is not warranted
- Calling-window hours, DNC handling, state insurance rules, retention periods, and carrier requirements change over time and vary by jurisdiction.
- Any calling-window tables, state rules, product notes, glossaries, or carrier references built into the Service are conveniences only. We do not warrant that they are current, accurate, or complete.
- Your agency is responsible for keeping its own configuration, suppression lists, disclosures, and policies current, and for verifying them against primary sources.
Your records, your retention obligations
- Your agency is the owner and controller of its client, lead, policy, and producer records. We process that data as your service provider, on your instructions, to provide and support the Service.
- Your agency is responsible for its own records-retention and destruction obligations, including state producer recordkeeping duties, and for exporting copies it needs to keep independently.
Access and authentication
- Every account is tied to a verified email address and a single agency workspace.
- Multi-factor authentication is required before any authenticated page or client record can be reached.
- Roles limit what a user can see and do: platform admin, agency owner, admin, manager, agent, and assistant.
- Agency owners and admins approve, suspend, or restore teammate accounts; removed users lose access immediately.
Platform and hosting
- Astralscrm runs on Lovable Cloud, a managed backend platform built on Supabase infrastructure.
- Database traffic is encrypted in transit using TLS. Database storage is encrypted at rest by the platform provider.
- The application is served from a globally distributed edge network and preview/staging builds are isolated from production.
- We do not run our own data centers or maintain physical access to the infrastructure.
Data collection and use
- We collect account information, user activity, and the customer data you choose to upload: leads, clients, policies, carrier contracts, and intake responses.
- Customer Data is owned by you. We process it only to provide, secure, and support the Service.
- Sensitive fields such as government identifiers, dates of birth, and banking details are stored in access-controlled vault storage with limited retention.
- We do not sell personal information or use it for advertising model training.
Subprocessors and integrations
- The core subprocessors are Lovable Cloud / Supabase (database, auth, storage, and edge functions).
- Optional integrations such as email, calendar, and payment providers are enabled only when you connect them and are governed by their own terms.
- We review integrations for security and data-handling practices before making them available.
Cookies and analytics
- We use strictly necessary cookies to keep you signed in and to remember your display preferences.
- We may use privacy-preserving analytics to understand feature usage and to improve performance.
- We do not use third-party advertising or behavioral tracking cookies.
Retention and deletion
- Live business records — clients, policies, leads, and agent files — are not auto-deleted. They remain in the system indefinitely while your workspace is active, consistent with common state producer record-keeping duties of five or more years after a policy or client relationship ends.
- Exact retention duration is state-specific; agency owners should confirm the requirements for every state they operate in.
- Deleting a client, lead, or policy in the app is a soft delete: the record is hidden from day-to-day views but preserved, and an agency owner or admin can restore it from the Admin Console.
- Short-lived E-App intake links and PII vault staging rows are the exception — they are automatically purged after 72 hours.
- Agency owners and admins can export agency leads, clients, and policies to CSV at any time from the Admin Console.
Backups and recovery
- Automated point-in-time database backups and snapshots are taken by the managed platform and retained for 30 days for disaster recovery.
- Backups are a disaster-recovery control, not a records-retention archive: they exist so we can restore the platform, and they are separate from the indefinite retention of your live business records described above.
- Agency owners can take their own CSV exports of leads, clients, and policies at any time as an independent copy.
Audit and logging
- Sensitive reads, exports, downloads, and administrative actions are recorded with the actor, timestamp, IP address, resource, and reason code.
- The log is append-only within the application and can be exported for internal review or examination by agency owners and admins.
- The activity log is a recordkeeping aid, not a substitute for your own recordkeeping program, your regulator examination requirements, or a legal determination of any kind.
Security contact and incidents
- Report security concerns, suspected vulnerabilities, or unauthorized access to security@astralscrm.com.
- We will acknowledge receipt and provide a status update according to the severity of the report.
- If we discover a breach affecting your workspace, we will notify the agency owner without undue delay and cooperate with required notifications.
Shared responsibility
We secure the platform, but each agency controls who is invited, what roles they receive, what data is uploaded, and how the Service is used with consumers and carriers. Security works only when both sides keep their part of the agreement.
Last updated: September 2026. Questions? Contact security@astralscrm.com.