← Back to HomeSecurity & Trust
Last updated: June 23, 2026
CrewForce handles your calls, customer records, and payments, so security is foundational. Here’s how we protect your data — in plain English.
Data protection
- Encryption in transit: all traffic over TLS 1.2+ (HTTPS).
- Encryption at rest: sensitive credentials (e.g., CRM tokens) are encrypted with AES-256-GCM; databases are encrypted at rest.
- Least privilege: access to production is restricted and key-based; secrets are never stored in code.
- Backups: automated daily database backups.
- Monitoring: infrastructure and agent health are monitored continuously, with automated alerts.
Payments (PCI)
Card payments are handled entirely by Stripe. Card numbers never touch CrewForce servers — we only store a Stripe customer token. This keeps us within Stripe’s PCI-DSS SAQ-A scope.
AI calls & recording
- Our AI voice agent discloses at the start of every call that the caller is speaking with an AI assistant and that the call may be recorded.
- This disclosure is applied on every call nationwide, satisfying all-party (two-party) consent in states that require it.
- Recordings and transcripts are stored securely and used only to provide and improve the service.
Your data, your control
Incident response
If we become aware of a breach affecting your data, we will investigate promptly and notify affected customers without undue delay, consistent with applicable law.
Certifications roadmap (honest status)
CrewForce is built to a SOC 2-aligned posture (MFA, least-privilege, encryption, logging, backups, written policies). We are not yet SOC 2 Type II or ISO 27001 certified — those formal audits are planned as we scale and as enterprise customers require them. We’d rather tell you exactly where we are than imply a badge we don’t hold.
Security questions or to request our DPA: info@crewforce.cloud