trust · security

Security, stated plainly.

Where your data lives, how it's protected, and what we don't claim. No badge wall. We won't list a certification we haven't earned.

vault · counter-rotating
256-bit
aes encryption at rest
tls 1.3
in transit, every connection
99.5%
monthly uptime target
4h
incident response, business hours

the posture

How your data is held.

Six facts, no adjectives. The privacy policy carries the full text.

Where your data lives

Your database and application servers run on Railway, hosted in the EU. Static files are served from Cloudflare's global edge network. Your data doesn't move outside these systems except to the sub-processors listed below.

Encryption

AES-256 at rest, managed by Railway. TLS 1.3 in transit for every connection between you, Crewspace, and the tools we connect to.

Identity & access

Sign-in is handled by Better Auth; sessions refresh every 30 days. Role-based access controls apply inside your workspace, and our staff need MFA to touch production. Connecting Microsoft 365 uses Microsoft's own secure sign-in. Your admin approves access once.

Approval gates & audit log

Agents draft; you approve what matters. Every agent tool call writes a row to the audit log (timestamp, actor, agent, tool, target) so an admin can always answer who did what, as whom, and when.

Backups & availability

Regular backups on a 90-day rolling window. We target 99.5% monthly uptime; an Enterprise SLA is available on request.

How the AI runs

Your crew runs on built-in Crewspace AI. We route inference through our managed model provider, meter every unit and cap it on a live dashboard, so there are no keys to wire and no runaway spend. Enterprise can run its own internal LLM with data kept in-house. Get in touch.

sub-processors

Who touches your data.

The third parties that process customer data on our behalf, with their role and region.

Sub-processorRoleRegion
Fireworks AIManaged model provider: runs your AI agents on built-in Crewspace AIUS
OpenAIOptional voice & document-search featuresUS
MicrosoftGraph API for M365 integrationEU / customer-tenant
RailwayApplication hostingEU
CloudflareCDN + DNSGlobal
SendGridTransactional email when shippedEU
StripeBilling & paymentsEU

certifications · compliance

What we can claim today.

An honest account. Badges appear here when they're earned, not before.

in progress

SOC 2 Type II

We have not yet engaged an auditor. We expect to begin Type I in Q3 2026. Until it's done, no badge.

registered

UK GDPR

GDPR-compliant as data controller for the customer data we hold. ICO registration ZC159929: Tier 1, registered 29 May 2026. Complaints go to ico.org.uk.

on request

Data Processing Agreement

Our DPA template is available to any customer or prospect on request.

Request the DPA v0.1, legal review pending

contact · disclosure

If something goes wrong.

One address for both. It reaches people who can act.

Incident response

Email security@crewspace.ai. We aim to respond within 4 business hours.

Reporting a vulnerability

Found something? Same address: security@crewspace.ai. Good-faith research and responsible disclosure are welcome, and we won't pursue action against researchers acting in good faith.

Ask the hard questions.

Send your security questionnaire, request the DPA, or read the privacy policy: plain English first, full text after.