Security & Privacy

Your security and privacy are our top priorities. Learn about our comprehensive security measures, the standards we are building toward, and our data protection practices.

Comprehensive Security Measures

Multi-layered security architecture protecting your data at every level

Enterprise-Grade Security

Infrastructure with controls designed against SOC 2 criteria, monitoring, and threat detection.

  • Controls designed against SOC 2 criteria
  • 24/7 Security Monitoring
  • Threat Detection & Response
  • Incident Response Plan
Data Encryption

End-to-end encryption for data at rest and in transit using industry-standard protocols.

  • AES-256 Encryption at Rest
  • TLS 1.3 for Data in Transit
  • Encrypted Database Storage
  • Secure Key Management
Access Control

Multi-factor authentication and role-based access control for enhanced security.

  • Multi-Factor Authentication
  • Role-Based Access Control
  • Single Sign-On (SSO)
  • API Key Management
Privacy Protection

Data handling designed around GDPR and CCPA principles with comprehensive privacy controls.

  • GDPR-aligned practices
  • CCPA-aligned practices
  • Data Minimization
  • Right to Deletion
Secure Infrastructure

Cloud-native architecture with automated security updates and monitoring.

  • AWS Security Best Practices
  • Automated Security Updates
  • Network Segmentation
  • DDoS Protection
User Security

Advanced user authentication and session management for secure access.

  • Password Policy Enforcement
  • Session Management
  • Account Lockout Protection
  • Security Notifications

Standards We Are Building Toward

The security and privacy frameworks that guide how we build CrewFoundry

CrewFoundry is pre-launch — these reflect the standards we are building toward, not certifications we currently hold.

SOC 2

Controls designed against SOC 2 criteria; formal audit planned post-launch

Building toward

ISO 27001

Security practices modeled on the ISO 27001 framework

Building toward

GDPR

Data handling designed around GDPR principles

Aligned

CCPA

Data handling designed around CCPA principles

Aligned

Security Policies & Documentation

Detailed policies and procedures governing our security practices

Security Policy

Comprehensive security policy covering all aspects of data protection

PDF • 2.1 MB
Updated: 2024-01-15

Privacy Policy

How we collect, use, and protect your personal information

PDF • 1.8 MB
Updated: 2024-01-10

Data Processing Agreement

Terms for processing personal data in compliance with GDPR

PDF • 1.2 MB
Updated: 2024-01-05

Incident Response Plan

Our procedures for responding to security incidents

PDF • 900 KB
Updated: 2024-01-01

Recent Security Updates

Latest security enhancements and updates to our platform

Security Enhancement: Enhanced MFA

Enhancement

Implemented additional multi-factor authentication options including hardware tokens and biometric authentication.

2024-01-15

Security Patch: API Rate Limiting

Patch

Enhanced API rate limiting to prevent abuse and ensure service availability.

2024-01-10

Compliance Update: GDPR Enhancements

Compliance

Updated data processing procedures to enhance GDPR compliance and user privacy controls.

2024-01-05

Security Questions?

Have questions about our security practices? Our security team is here to help.

We use essential cookies to run this site, and — with your consent — analytics to improve it. No analytics or tracking runs until you allow it. See our Cookie Policy.

Preferences