trust · security
Security, stated plainly.
Where your data lives, how it's protected, and what we don't claim. No badge wall. We won't list a certification we haven't earned.
the posture
How your data is held.
Six facts, no adjectives. The privacy policy carries the full text.
Where your data lives
Your database and application servers run on Railway, hosted in the EU. Static files are served from Cloudflare's global edge network. Your data doesn't move outside these systems except to the sub-processors listed below.
Encryption
AES-256 at rest, managed by Railway. TLS 1.3 in transit for every connection between you, Crewspace, and the tools we connect to.
Identity & access
Sign-in is handled by Better Auth; sessions refresh every 30 days. Role-based access controls apply inside your workspace, and our staff need MFA to touch production. Connecting Microsoft 365 uses Microsoft's own secure sign-in. Your admin approves access once.
Approval gates & audit log
Agents draft; you approve what matters. Every agent tool call writes a row to the audit log (timestamp, actor, agent, tool, target) so an admin can always answer who did what, as whom, and when.
Backups & availability
Regular backups on a 90-day rolling window. We target 99.5% monthly uptime; an Enterprise SLA is available on request.
How the AI runs
Your crew runs on built-in Crewspace AI. We route inference through our managed model provider, meter every unit and cap it on a live dashboard, so there are no keys to wire and no runaway spend. Enterprise can run its own internal LLM with data kept in-house. Get in touch.
sub-processors
Who touches your data.
The third parties that process customer data on our behalf, with their role and region.
| Sub-processor | Role | Region |
|---|---|---|
| Fireworks AI | Managed model provider: runs your AI agents on built-in Crewspace AI | US |
| OpenAI | Optional voice & document-search features | US |
| Microsoft | Graph API for M365 integration | EU / customer-tenant |
| Railway | Application hosting | EU |
| Cloudflare | CDN + DNS | Global |
| SendGrid | Transactional email when shipped | EU |
| Stripe | Billing & payments | EU |
certifications · compliance
What we can claim today.
An honest account. Badges appear here when they're earned, not before.
SOC 2 Type II
We have not yet engaged an auditor. We expect to begin Type I in Q3 2026. Until it's done, no badge.
UK GDPR
GDPR-compliant as data controller for the customer data we hold. ICO registration ZC159929: Tier 1, registered 29 May 2026. Complaints go to ico.org.uk.
Data Processing Agreement
Our DPA template is available to any customer or prospect on request.
contact · disclosure
If something goes wrong.
One address for both. It reaches people who can act.
Incident response
Email security@crewspace.ai. We aim to respond within 4 business hours.
Reporting a vulnerability
Found something? Same address: security@crewspace.ai. Good-faith research and responsible disclosure are welcome, and we won't pursue action against researchers acting in good faith.
Ask the hard questions.
Send your security questionnaire, request the DPA, or read the privacy policy: plain English first, full text after.