Learn · Intake & CRM privacy
Why your intake and CRM must be encrypted.
The inquiries that come in through your website — and the pipeline they become — are the most sensitive asset most small teams own: clients, candidates, prospects, the notes you’d never want read aloud. The uncomfortable truth is that most tools that catch and store them can read every word. That’s a choice, not a law of nature.
A readable CRM is a copy of your business in someone else’s hands.
When a provider can read your CRM, so can everyone who can reach the provider. These are the six ways a “normal” CRM quietly leaks — each one closed by default when the data is encrypted end-to-end.
- Vendor data breaches.If your CRM vendor is breached, attackers get your plaintext client list, contact details, and notes. With end-to-end encryption, a breach leaks only ciphertext — useless without your key.
- Subpoenas and legal discovery.A readable CRM hands over your full pipeline on request — you may never even hear about it. A zero-knowledge CRM can only produce ciphertext, because the vendor never held the key.
- AI training on your data.Many CRMs feed your notes and contacts into models for “insights” — often opt-out, not opt-in. A vendor that literally cannot read your data cannot train on it.
- Insider and rogue-employee access.Support staff, admins, and engineers at a typical CRM can usually read customer records. End-to-end encryption removes that access entirely — there is nothing in plaintext to look at.
- Third-party integrations.Every integration that “syncs” your CRM copies your data somewhere new — another company, another breach surface. Fewer copies in plaintext means fewer ways to leak.
- “Encrypted at rest” theater.Most “secure CRM” claims mean encrypted-at-rest: the vendor still holds the key and can read everything. That protects them from a stolen hard drive, not you from the vendor.
End-to-end, in three moves.
The key is born on your device and never leaves it — here’s what that buys you.
Sealed in their browser.
When you set your password, your browser derives an encryption key locally — on your device, from a secret only you know. That key is never sent to Brun in a form we can read. Every lead, note, and contact field gets encrypted the same way, before it ever leaves your screen.
Step 2 · End to end
End-to-end means we store gibberish.
“End-to-end” means the data is encrypted on your device and stays encrypted until it reaches another device on your team. In between — on the network, in the database, in a backup, in a subpoena response — it is ciphertext. The provider never holds the key, so there is nothing to read, sell, train on, or surrender.
A real lead record.
stored on our serversNo name, no email, no notes — exactly as it sits on our servers. That is the whole idea behind a zero-knowledge CRM.
Unlocked on your board.
Decryption happens in your teammates’ browsers, with keys only they hold. Brun, an attacker, and a subpoena all see the same thing: gibberish. Only the people you actually work with ever see the words.
Encrypted at rest vs. end-to-end encrypted.
Almost every CRM calls itself secure. The table below shows what that claim actually covers, and who ends up holding the key.
| Encrypted at rest | End-to-end encrypted | |
|---|---|---|
| Who holds the key | The vendor | Only your team |
| Can the vendor read your data | Yes | No — ever |
| What a breach leaks | Plaintext records | Ciphertext only |
| What a subpoena returns | Plaintext records | Ciphertext only |
| Can it be used to train AI | Technically yes | Impossible |
| Protects against | A stolen disk | Everyone, including us |
Teams where one leak ends the relationship.
- Recruiters & search firmsCandidate pipelines that can’t sit in someone else’s database.
- Lawyers & advisorsClient matters that have to satisfy a duty of confidentiality.
- Therapists & coachesFirst-contact inquiries that must never become a breach disclosure.
- Brokers & financial advisorsProspect and client lists kept off everyone else’s servers.
- Founders running salesDeal flow you control without handing it to a third party.
Encryption questions, answered.
What is an end-to-end encrypted CRM?
A CRM where your data is encrypted on your device, before it reaches the provider, and can only be decrypted by you and your team. The provider stores and serves ciphertext it cannot read. This is also called a zero-knowledge CRM.
Isn’t “encrypted at rest” good enough?
Encrypted at rest means the vendor encrypts data on their disks but still holds the keys — so the vendor, their staff, an attacker who gets in, and a subpoena can all still read it. End-to-end encryption removes the vendor’s ability to read your data at all.
What does “zero-knowledge” mean for a CRM?
It means the provider has zero knowledge of your actual content. Brun knows your account email and billing status, but the leads, contacts, and notes are encrypted with a key we never hold — so we can’t read, sell, train on, or hand over your data.
What’s the tradeoff?
Because we can’t read your data, we also can’t recover it. If the last person on your team loses both their password and your recovery key, the data is gone for good. Real encryption means you hold the only keys — so guard them.
Inquiries only you can read
Stop handing your inquiries to a vendor.
Brun protects the same thing for every team: the inquiry is encrypted the instant it leaves the visitor’s browser, so what we store is ciphertext, and what your team sees is a lead on a simple board. Keep the form you have, connect it in two changes, and start today.