← Back to Home

Security & Trust

Last updated: June 23, 2026

CrewForce handles your calls, customer records, and payments, so security is foundational. Here’s how we protect your data — in plain English.

Data protection

Payments (PCI)

Card payments are handled entirely by Stripe. Card numbers never touch CrewForce servers — we only store a Stripe customer token. This keeps us within Stripe’s PCI-DSS SAQ-A scope.

AI calls & recording

Your data, your control

Incident response

If we become aware of a breach affecting your data, we will investigate promptly and notify affected customers without undue delay, consistent with applicable law.

Certifications roadmap (honest status)

CrewForce is built to a SOC 2-aligned posture (MFA, least-privilege, encryption, logging, backups, written policies). We are not yet SOC 2 Type II or ISO 27001 certified — those formal audits are planned as we scale and as enterprise customers require them. We’d rather tell you exactly where we are than imply a badge we don’t hold.

Security questions or to request our DPA: info@crewforce.cloud