Modern Trades CRMRequest Info

Security

Security -- What's Verified, What's Not

This page lists only what has been independently checked about how this site and Modern Trades CRM handle data. Where something hasn't been verified, it's labeled UNKNOWN rather than assumed.

This Website

  • Hosting: This marketing site is hosted on Vercel, which provisions HTTPS/TLS automatically for the custom domain -- verified live on moderntradescrm.com.
  • No credentials in this site's code or configuration: As of this review, this project has zero environment variables configured on its Vercel deployment -- verified via the Vercel CLI. No CRM credentials, API keys, or tokens are wired into this website, client-side or server-side.
  • No live data collection yet: The contact and request access pages do not submit to a live form or database -- they link out to a working contact channel instead. Nothing typed into this site is currently stored by it.

The CRM Platform

Modern Trades CRM is built on GoHighLevel, a third-party SaaS CRM platform -- the underlying contact, pipeline, and workflow data lives there, not in this website's code.

  • Consent fields: SMS and email consent status, source, and timestamp fields exist on the contact record (verified built as of 2026-08-25). Whether an automation currently enforces those consent values before sending is a separate question -- see the capabilities matrix.
  • Access controls: Not yet independently documented on this page. User-level permissions within the platform are managed by the account owner; specifics have not been published here.
  • Encryption specifications, SOC 2 or other compliance certifications, uptime guarantees, disaster-recovery/backup posture: UNKNOWN -- not independently verified as of this review. We are not publishing a claim about any of these until it has been confirmed directly, and we will not describe GoHighLevel's infrastructure using language we haven't verified against their own current documentation.

Data Minimization

No form on this site currently collects information, so there is currently nothing to minimize on the website side. When a live form is connected, it will collect only the fields needed for the stated purpose, with consent state tracked per the fields above -- and this page will be updated to reflect what actually goes live, not what's planned.

Customer Responsibilities

Once live, account owners are responsible for who on their team has access to their CRM account, for honoring consent and opt-out requests they receive directly, and for their own compliance obligations (e.g. TCPA consent requirements -- see the Phone & SMS Readiness guide) under any applicable law.

Known Limitations

This page reflects a review conducted 2026-08-25 against this repository's configuration, this site's Vercel deployment settings, and the available internal build-status notes for the CRM platform account. It does not reflect a third-party security audit or penetration test -- none has been conducted. Items marked UNKNOWN above will be updated only once independently confirmed, not assumed favorably.

Last reviewed 2026-08-25.