Sign-in is handled by a dedicated authentication provider. Every action in the product is scoped to your company through per-company access controls and membership checks, so one account cannot reach another company’s workspace.
Each company’s data is isolated. Every record is tied to your company, and that boundary is enforced across the platform and covered by a dedicated set of isolation tests, so your workspace stays separate from every other customer.
When you connect a business tool, the credentials and any stored secrets are encrypted at rest using AES-256-GCM. We keep the minimum needed to operate your integrations, and connected-tool access is revoked when you remove a company.
High-risk actions your AI employees attempt are screened and held for your approval before they run. You stay in control of anything that touches money, customers, public communications, or external systems.
Security events and account activity are logged, and the platform is monitored with error tracking so we can detect, investigate, and respond to issues. We follow documented incident-response and data-request runbooks.
Security is shared. A few habits keep your workspace and your connected tools safe:
If you believe you have found a security issue, please email support@ceocrew.app. We welcome responsible disclosure and will work with you to confirm and address valid reports.