← crewbrief.co
Version 1.0 · Effective 2026-05-28

Information Security — Public Summary

Plain-language summary: CrewBrief stores sensitive credentials and personal data. We protect them with TLS, AES-256-GCM application-layer encryption, passkey-only authentication, principle of least privilege, and a 72-hour breach notification commitment. The full internal Information Security Policy is available on request to qualifying partners (banking, vendor risk reviews, audit).

1. Encryption

2. Authentication and access

3. Data minimization

4. Logging and monitoring

5. Incident response

6. Vulnerability disclosure

If you believe you have found a security vulnerability, email security@crewbrief.co with details and reproduction steps. We will:

Please do not run scanners or load tests against the production system without prior written permission.

7. Third-party processors

Material data processors used by CrewBrief include (subject to change):

The current list of subprocessors is documented internally and can be provided to qualifying partners (e.g., bank/vendor risk reviews) on request.

8. Full Information Security Policy

The complete internal Information Security Policy (covering staffing, access reviews, change control, asset inventory, penetration testing schedule, and disaster recovery objectives) is available on request to enterprise partners and auditors. Email security@crewbrief.co with the subject "InfoSec Policy request" and brief context (organization, role, intended use).

9. Contact

security@crewbrief.co