Workspace isolation
Protected records and actions are scoped to the signed-in user’s active company workspace. Cross-workspace access is rejected.
SECURITY AND DATA HANDLING
Crewline is designed around company isolation, least-privilege access, encrypted contractor information and auditable approvals. These are the current product controls—not certification claims.
Protected records and actions are scoped to the signed-in user’s active company workspace. Cross-workspace access is rejected.
Owner, administrator, staff and onboarding roles receive different access. Sensitive contractor details are limited to authorized owners and administrators.
Sensitive onboarding fields are encrypted with AES-GCM before database storage. Encryption keys are kept outside the application database.
Uploaded evidence is stored under company and event boundaries. File type, size and content signatures are checked before acceptance.
Crew onboarding and signature journeys use scoped, expiring links. Reissued signature requests supersede older links.
Material workspace actions record the company, actor, event, entity, action and timestamp for operational review.
Crewline separates settlement approval, payment scheduling, sending and confirmed payment. Crew payments are executed through the customer’s approved providers.
Sensitive profile responses are marked private and non-cacheable. File and payment evidence includes integrity hashes where the workflow requires them.
CLEAR BOUNDARIES
Financial actions remain with the customer and its approved providers.
Vendor setup and approved imports can store banking and tax details in Crewline. These fields are encrypted, restricted to authorized owners and administrators, and access is logged.
Pilot documentation distinguishes implemented controls from customer-specific contractual requirements.
Security questionnaires, contractual commitments, incident contacts and data-processing terms are confirmed during pilot scoping. See the privacy policy for product-specific privacy information.