Security at Anvil CRM

Straightforward security and data controls for your CRM.

Security should support everyday work without getting in the way. Anvil gives teams clear sign-in, roles, permissions, activity history, connected AI controls, and practical ways to manage access and data.

Core controls

The controls teams expect, without extra complexity.

Secure sign-in

Anvil checks every signed-in session on the server before showing or changing CRM data.

Roles and permissions

Workspace roles, granular permissions, record grants, pipeline visibility, and plan entitlements determine what each person can read or change.

Two-factor authentication

People who sign in with a password can add an authenticator app and backup codes for an extra verification step. Trusted-device controls reduce repeated prompts on approved devices.

Controlled AI connections

Compatible AI clients connect through OAuth 2.1. People choose a workspace and approve explicit access, while admins decide whether connected AI may read or write.

Clear activity history

CRM changes appear in record timelines. Connected AI actions record who connected, the tool used, the outcome, and affected record identifiers without storing prompts or customer field values in the tool-call log.

Simple access and data control

People can revoke their own AI connections, and admins can remove any connection. Standard and Pro support CRM import and export. Pro adds audit and deleted-record recovery tools.

Connected AI

AI connections stay within the access you approve.

Anvil uses OAuth 2.1 to connect compatible AI clients. During setup, the person selects a workspace and approves the requested access. Each action is checked against current plan, role, record, and pipeline permissions. Turning off write access makes the connection read-only.

Sensitive actions require explicit confirmation. People can revoke their own connection, admins can remove any connection, and disabling connected AI access stops later calls. Read the technical overview on the CRM with MCP page before connecting a client.

Review Anvil MCP controls

Report a concern

Contact the Anvil team

Send security, privacy, or data-control questions to support@anvilcrm.com. Include the affected URL, date, and a concise description. Do not email passwords, API keys, session cookies, access tokens, or unredacted customer exports.