How we connect

Every integration uses the vendor's official, documented API — Salesforce, HubSpot, SAP, Microsoft Graph, Google Workspace, Stripe, your banking provider, and so on. We do not screen scrape, we do not automate a browser session against your systems, and we never ask for a shared user login.

Least privilege by default
Each connection is granted the narrowest scope that makes the console work. Read-only wherever read-only is sufficient. Write scopes are requested per use case, named explicitly during the design phase, and listed in your build documentation.
Credentials and tokens
OAuth wherever the vendor supports it, so you can revoke access from your own admin console at any time without contacting us. Where only API keys exist, they are held in a managed secret store, never in source control, configuration files or spreadsheets.
Revocation
You can cut every connection yourself, from your own systems, without our involvement. We consider that a feature rather than a risk.

What we store, and what we do not

Your systems remain the systems of record. The console holds the minimum needed to render views quickly — typically identifiers, the fields shown on screen, and a short-lived cache. The precise cached fields and retention period are agreed with you during design and written into your build documentation.

  • We do not sell your data, and we do not share it with advertising or data brokers.
  • We do not use your data to train machine learning models, ours or anyone else's.
  • Data in transit is encrypted with TLS. Data at rest is encrypted by the hosting platform.
  • Access to your environment is limited to the people working on your build, and is logged.

The AI layer

Summaries, suggested next steps and momentum signals are generated by sending the relevant record context to a large language model provider. Three commitments about that:

  • We use providers under agreements that prohibit training on submitted content, and we configure zero-retention options where the provider offers them.
  • We agree with you in advance which record types and fields may be sent, and exclude anything you designate as off limits.
  • The AI layer proposes; it does not act unilaterally. Drafts and suggested actions are reviewed by a person before anything is written back to your systems, unless you explicitly ask us to automate a specific step.

The named model providers and their current data-processing terms are listed in the sub-processor schedule, available on request and attached to your DPA.

Access control inside the console

Permissions are set by user or by role, and apply at four levels:

Module
Whether someone sees Sales, Finance, Operations, People, Tasks or Files at all.
Record
Which accounts, jobs or invoices are in scope — by territory, owner or custom rule.
Field
Individual fields can be hidden, so a service engineer can see the installation without seeing the margin.
Mode
View-only and view-as, so a manager can confirm exactly what a team member sees without borrowing their account.

GDPR and data processing

For personal data flowing through the console, you are the controller and Consolo acts as a processor on your instructions. We will sign a Data Processing Agreement covering purpose limitation, sub-processors, security measures, breach notification, assistance with data subject requests, and deletion or return of data at the end of the engagement.

Hosting is in the EU by default. If you need a specific region or a dedicated environment, we will scope and price that specifically, and confirm feasibility during the audit.

If something goes wrong

If we become aware of a security incident affecting your data, we will notify your named contact without undue delay and no later than 48 hours after confirming it, with what we know, what we are doing, and what we need from you. We would rather tell you early and be wrong about the severity than tell you late.

What we ask of you

Security is shared. We ask that you nominate an internal owner for access decisions, use SSO and multi-factor authentication on the underlying systems, and tell us promptly when someone with console access leaves.

Questions we are happy to answer

Security questionnaires, architecture calls with your IT function, and reviews with an external auditor are all normal parts of this process. Write to consolo@bashara.pt and we will get the right detail in front of the right person.

Book your free integration audit