Skip the CRM build. Keep the control.
Opens an email to enterprise@custral.com.
Sample workspace
Price the build before you start it.
Building costs $10,672,668 more over 3 years.
No AI model or audit fees, so the build side is the low estimate
Engineers: the median salary for software developers, $135,980 in May 2025 (US Bureau of Labor Statistics, checked September 2026), plus 43% for benefits and payroll costs, since wages are 70% of what private employers spend on compensation (BLS, June 2026, checked September 2026). Every seat, checked September 2026: email and calendar sync $1.75 a seat a month on Nylas; phone number $1.15 a seat a month on Twilio; calling $0.014 a call minute on Twilio; call recording $0.0025 a call minute on Twilio; call transcripts $0.0048 a call minute on Deepgram; meeting recording and transcripts $0.65 a meeting hour on Recall.ai; servers and databases $0.50 a seat a month, the low end of SpendArk's third-party estimate. It leaves out AI model fees, calling to other countries and the SOC 2 audit. Custral's price is Scale on our pricing page, billed annually.
What the build has to cover, and where it stands in Custral
- Access control
- Calls and texts
- Meetings
- Stella
- Workflows
- Forms and booking
- Web, desktop and mobile
- Chrome extension
- Sandboxes
- SOC 2 Type II in progress
What each one takes to build
Your engineers build on the same records.
import {Custral} from "@custral/sdk";
const custral = new Custral({apiKey: process.env.CUSTRAL_API_KEY});
// Create a record on any object, by its key
const {id} = await custral.records.create({
object: "deals",
fields: {name: "Northwind renewal", stage: "Discovery"},
});
// Later, when billing confirms the contract
await custral.records.update({
object: "deals",
id,
fields: {stage: "Closed won"},
});REST endpoints for records, objects, conversations, documents and usage, with a TypeScript SDK and a CLI.
$ claude mcp add --transport http custral https://api.custral.com/v1/mcp
YouWhich renewals over $40k are still in discovery? Move Northwind to Proposal.Toolsearch_records deals · "renewal"3 recordsToolupdate_record Northwind renewal · stage: ProposalUpdatedSign in through the browser and pick the workspace. There is no key to copy.
Paste a page into an Embed block and it runs sandboxed, with no access to your records. A block built to read them gets a short-lived token, capped at the viewer's own access.
import express from "express";
import {Custral} from "@custral/sdk";
const custral = new Custral({apiKey, webhookSecret});
// Keep the warehouse in step with every record change
custral.on("record.updated", (event) => warehouse.upsert(event.data));
const app = express();
app.post(
"/webhooks/custral",
express.raw({type: "application/json"}),
custral.webhooks.express(),
);Every delivery is signed with HMAC-SHA256, verified by the SDK, and retried if it fails.
Decide who can see, change and connect.
A grant is one sentence.
Who, over what, at which level. Everything below inherits it, unless you set something to stop inheriting.
How permissions work →has on .
Can edit. Change values and content, but not delete or share. Every Deal inherits it, unless one is set to stop inheriting.
It stops and shows you the write.
In Ask first, the default, Stella pauses before a write and shows it filled in. Reads never ask. Auto stops only before something destructive.
How Stella asks →Northwind renewal in Deals
- stage
- Closed won
- contract_value
- 48,000
- owner
- Dana Whitfield
Pick one to see what it does.
Every key acts as the teammate who made it.
An API key reaches what that person can, within the scopes you grant. Revoke a leaver's keys under Settings → Applications.
See what they can build →Where we actually are on security.
- Encryption in transit and at rest
TLS in transit, encrypted at rest on managed AWS.
In place - Access to the object, page and record
Granted to a person, a team or everyone in the workspace.
In place - Two-factor sign-in
Authenticator app codes, with recovery codes.
In place - Managed cloud
Runs on AWS. Nothing self-hosted for you to patch.
In place - SOC 2 Type II
Underway with our auditor. The report is shared under NDA once it is complete.
In progress
Monitored continuously by Oneleet
The badge is live, so it changes the day the examination finishes.
A rollout with nobody on retainer.
Build in a sandbox
- Import a sample from a spreadsheet
- Shape objects, views and workflows
- Grant teams access
- IT reviews, then Go live
Invite teams
- Run the full import on the live workspace
- Web, desktop, mobile and Chrome, one login
Connect your tools
- HubSpot, Stripe and GitHub sync into linked tables
- Slack connects as an inbox channel
Wire it inEngineering
- The warehouse subscribes to webhooks
- AI tools connect over MCP
Questions enterprise buyers ask.
Is it really cheaper than building our own?
Try your own numbers above. The build side counts engineers with their benefits, and the software and servers every seat needs, but no AI model or audit fees, so it's the low estimate.
What can our engineers build on it?
Anything the API reaches: records, objects, conversations, documents and usage, from the SDK, the CLI or plain HTTP. API access starts on Growth.
Can an integration see more than it should?
An API key reaches what its creator can, within its scopes. Keys are listed under Settings → Applications, which is where you revoke a leaver's keys.
How does pricing compare with Salesforce and HubSpot?
See our dated, sourced comparisons: Custral vs Salesforce and Custral vs HubSpot. Plans run from Starter to Scale; Enterprise is quoted.
Where are you on SOC 2?
Type II is in progress with our auditor, and Oneleet monitors our controls continuously. We'll walk your team through today's controls and share the report under NDA once it's complete.
Bring us the CRM you were about to build.
One call covers what you'd build, what's already here, and how your engineers extend it.