Security

A careful approach, described without overclaiming.

We take the security and reliability of CrewInn seriously and prefer to describe what we do plainly. The points below reflect our approach; they are not formal certifications or guarantees.

Role-based permissions

Access is designed to be granted by role; role-based permissions are being developed.

In development

Tenant separation

The platform is designed to keep each organisation's workspace separate from others.

Platform design principle

Audit history

A history of key actions is being developed to support accountability and review.

In development

Backups

Keeping backups is part of our operational practice for running the service.

Operational practice

Recovery planning

Planning for recovery so we can restore service is part of our operational practice.

Operational practice

Controlled releases

Releasing changes in a controlled way, rather than ad hoc, is our operational practice.

Operational practice

Secure development practices

Careful development and review as we build is our operational practice.

Operational practice
What we do not claim. CrewInn does not currently claim formal certification, guaranteed compliance or uninterrupted availability. We do not display security seals, ISO or GDPR badges, and we do not claim “bank-grade” or “enterprise-grade” security, complete GDPR compliance, zero downtime or unlimited scale. Data-protection and processing terms for customer data will be covered by separate product agreements, which should be reviewed before any commercial use.

Questions about security?

Get in touch and we will talk through our approach for your organisation.