Core CRM security hardening

Run the post-upgrade security verification checklist

Verify every included hardening item before closing the release change.

Audience: Administrators and deployment engineersPermission: Core release / deployment authority
Exact navigationSupported Britixo CRM deployment and database-upgrade process — no staff menu route

What this guide covers

Verify every included hardening item before closing the release change. The workflow below follows the supported application or module flow and does not invent a menu or bypass validation.

Exact step-by-step process

  1. Use the supported Britixo CRM release or workflow that produces this security control.
  2. Verify the expected protection through an authorised test.
  3. Record the result in the deployment or security audit evidence.

Fields, choices and supported possibilities

  • Evidence for every included control
  • Change and rollback record

Code-backed validations and workflow rules

  • Confirm migrations 342 and 040.
  • Test staff/client login, 2FA and all throttles.
  • Verify Argon2id and a controlled phpass upgrade.
  • Test API-token expiry, revocation, rotation and metadata.
  • Inspect cookie flags, session regeneration, TLS, proxy, headers, CSP reports, audit events and web-server protections.
  • Provision one controlled future tenant.

Expected result and verification

  • The protection is active without weakening another security control.

Security, audit and troubleshooting checks

  • Use the exact authorised account, role and record before saving or sending.
  • Verify the saved status and downstream record; a browser success message alone is not sufficient evidence.
  • Never expose passwords, API keys, access tokens, protected attachments or raw server paths in support tickets.
  • Do not edit module or core database records directly to bypass validation, permissions, migrations or state rules.