The honest version, including the parts that are usually left out.
Other customers: never
Organizations are separated in the database itself. Every query is scoped to one organization before it runs, so there is no screen, no report and no API call that returns another organization's records. This is not a filter that could be forgotten on a new screen — it's a property of how data is fetched.
Your own colleagues: whatever their role allows
Inside your organization, visibility is decided by security roles. Someone with a limited role sees a limited product — screens they don't have permission for aren't hidden, they aren't there.
This is the part organizations most often get wrong, and it's entirely within your control. If somebody can see more than they should, the answer is their role. Security Roles Explained covers it.
Some data has narrower rules on top of roles. Knowledge base articles are addressed to specific audiences. Patient records are audited individually. Notes are private to the person who wrote them unless deliberately shared.
People at Kamo: rarely, deliberately, and recorded
This is the question people mean when they ask this question.
Kamo staff don't browse customer data. Access to a production system requires a specific reason, is time-limited, and is recorded. The most common case by far is a support engineer looking at a specific problem you've reported, on the record you've pointed them at.
There's a break-glass mechanism for genuine emergencies — data loss, a security incident — that grants elevated access for a short, fixed window. It's controlled by the server rather than by whoever is using it, it expires on its own, and it produces a record. It exists because the alternative, when something is genuinely wrong at 3am, is worse.
Your own AI provider: if you connect one
If your organization connects its own AI provider, the material the Assistant works with goes to that provider, under your agreement with them rather than ours. That's a deliberate choice you make — worth knowing you're making it.
What we log
Sign-ins, access to protected health information, and changes to security settings, among others. Logs exist so that "who saw this and when" has an answer, which is the only thing that makes any of the above verifiable rather than merely stated.
How to Review System Access Logs shows you your own.
Related articles
Other guides that answer questions close to this one.
Privacy and Compliance
What happens to your data, what we do and don't do with it, and the standards KamoCRM is built to align with. Your data is yours The information your organization puts into KamoCRM belongs to your organization. It isn't…
Where Your Data Is Stored
Three kinds of storage, holding three different sorts of thing. Records Anything with fields — leads, accounts, contacts, calendar events, timecards, settings — lives in a distributed SQL database. "Distributed" means…
How KamoCRM Is Built
You don't need to know any of this to use KamoCRM. It's here because IT teams, security reviewers and procurement people ask, and it's easier to hand them a page than to arrange a call. Many small services, not one big…