ISO/IEC 27001 Information Security
LastDatabase maintains an information security management program focused on protecting the confidentiality, integrity, and availability of information and supporting systems.
Our information security program includes administrative, technical, and operational controls supporting risk management, access control, application security, infrastructure protection, and security operations.
Infrastructure & Application Security
LastDatabase maintains security controls for the infrastructure and applications used to operate the platform.
Encrypted Connections
HTTPS/TLS protects supported communications between customers, integrations, and LastDatabase.
Infrastructure Protection
Production infrastructure uses administrative restrictions, monitoring, and access controls.
Application Security
Authentication, authorization, input handling, logging, and dependency management form part of application security.
Security Monitoring
Operational and security logging supports reliability, troubleshooting, and security investigation.
Authentication & Access Control
Access to LastDatabase systems is restricted according to authorization requirements and operational roles. Administrative access is limited to authorized personnel.
- Role-based application access controls.
- Restricted administrative access.
- Least-privilege security principles.
- Protected customer authentication.
- Authorization controls for protected platform functionality.
CRM & Third-Party Integrations
LastDatabase integrates with CRM and business platforms to help customers transfer authorized business records into their existing workflows.
Where supported by the provider, integrations use OAuth-based authorization. Customers authorize access through the applicable third-party authorization process rather than providing their CRM passwords to LastDatabase.
Integration credentials and authorization tokens are treated as sensitive information and are used for authorized integration functionality.
CRM, Browser Extension & Integration Security
LastDatabase integrates with CRM, sales, and browser-based workflow platforms to help customers use authorized LastDatabase functionality within their existing business workflows.
Integration security is based on provider-authorized authentication, controlled API access, restricted permissions, and protection of integration credentials and authorization tokens.
HubSpot Integration
The LastDatabase HubSpot integration connects supported LastDatabase workflows with HubSpot CRM using authorized integration and API mechanisms.
- Customers authorize their HubSpot connection.
- Integration access is used for supported CRM functionality.
- Authorization credentials and tokens are treated as sensitive information.
- Customers retain control over their connected HubSpot account.
Salesforce Integration
The LastDatabase Salesforce integration uses Salesforce-authorized authentication and API mechanisms for supported CRM functionality.
- Customers authenticate through Salesforce authorization mechanisms.
- LastDatabase does not require a customer's Salesforce password for OAuth-based integration.
- API access is limited to permissions required by enabled integration functionality.
- Customers control which authorized Salesforce organizations connect to LastDatabase.
- Customers can revoke integration authorization using supported Salesforce controls.
Zoho CRM Integration
The LastDatabase Zoho CRM integration enables supported LastDatabase and CRM workflows through authorized Zoho integration mechanisms.
- Customers authorize their Zoho CRM connection.
- API access is used for supported integration functionality.
- Integration authorization information is treated as sensitive information.
- Customers retain control of the connected Zoho CRM account and its authorization.
Google Chrome Extension
The LastDatabase Chrome extension provides supported LastDatabase functionality within the browser while communicating with authorized LastDatabase services.
- Extension functionality is limited to its stated LastDatabase workflow.
- Browser permissions should be limited to permissions required for enabled extension functionality.
- Authentication and protected LastDatabase operations remain subject to LastDatabase account authorization.
- Communication with LastDatabase services uses secure HTTPS connections.
OAuth & API Authorization
Where supported by an integration provider, LastDatabase uses OAuth or equivalent provider-authorized mechanisms instead of requiring customers to provide their third-party account passwords directly to LastDatabase.
API permissions are intended to be limited to functionality required for the integration features authorized by the customer.
Integration Credentials & Tokens
API credentials, authorization tokens, and other integration secrets are treated as sensitive information and are used only for authorized integration operations.
Customer Control
Customers control which supported accounts and services they connect to LastDatabase. Where supported by the third-party provider, customers can revoke or disconnect authorization through the provider or LastDatabase integration controls.
Additional Integrations
The same security principles apply as LastDatabase introduces additional CRM, browser, API, and business-platform integrations. Specific permissions and authorization methods can differ by provider and enabled functionality.
Vulnerability Management
LastDatabase evaluates security issues affecting its application, infrastructure, and software dependencies. Remediation is prioritized according to security risk and operational impact.
Security updates are deployed as appropriate based on severity, exposure, compatibility, and operational requirements.
Security Reporting
Customers, partners, and security researchers who identify a potential security issue should report it directly to LastDatabase with sufficient information for investigation.
Backup, Recovery & Business Continuity
LastDatabase maintains backup and recovery procedures for production systems. Operational processes support service restoration following infrastructure failures and other disruptive events.
Incident Response
LastDatabase maintains procedures for identifying, investigating, containing, remediating, and responding to information-security incidents.
GDPR & CCPA Compliance
Our privacy and data-governance framework includes processes for data-subject and consumer privacy rights, data access, deletion, correction, opt-out requests, suppression, security, and responsible processing of personal information.
LastDatabase maintains technical and organizational measures to protect personal information and processes for responding to GDPR and CCPA privacy requests.
Additional information is available in the LastDatabase CCPA & GDPR Privacy Compliance Statement.
Privacy Rights & Opt-Out Requests
Individuals may submit applicable privacy, suppression, and opt-out requests through the LastDatabase privacy request system.
Shared Security Responsibility
LastDatabase is responsible for security controls covering the LastDatabase platform and infrastructure under its control.
Customers are responsible for protecting their account credentials, configuring CRM permissions appropriately, controlling authorized users, and using exported information in accordance with legal and regulatory requirements applicable to their activities.
Third-Party Services
LastDatabase may use third-party infrastructure, payment, CRM, communications, security, and technology providers to deliver portions of its services. Third-party services maintain their own security and privacy responsibilities.