CeoCrewBack to home

Security

How we protect your business.

The measures we take to keep your data and your AI workforce safe, and the steps you can take to stay secure.

01Authentication and access control02Tenant isolation03Encrypted credentials and secrets04Approval gates for high-risk actions05Audit logging and monitoring06What you can do07Reporting a vulnerability
01

Authentication and access control

Sign-in is handled by a dedicated authentication provider. Every action in the product is scoped to your company through per-company access controls and membership checks, so one account cannot reach another company’s workspace.

02

Tenant isolation

Each company’s data is isolated. Every record is tied to your company, and that boundary is enforced across the platform and covered by a dedicated set of isolation tests, so your workspace stays separate from every other customer.

03

Encrypted credentials and secrets

When you connect a business tool, the credentials and any stored secrets are encrypted at rest using AES-256-GCM. We keep the minimum needed to operate your integrations, and connected-tool access is revoked when you remove a company.

04

Approval gates for high-risk actions

High-risk actions your AI employees attempt are screened and held for your approval before they run. You stay in control of anything that touches money, customers, public communications, or external systems.

05

Audit logging and monitoring

Security events and account activity are logged, and the platform is monitored with error tracking so we can detect, investigate, and respond to issues. We follow documented incident-response and data-request runbooks.

06

What you can do

Security is shared. A few habits keep your workspace and your connected tools safe:

  • Protect the account you sign in with, whether Google or email, using a strong, unique password and two-factor authentication where it is available.
  • Only connect tools and accounts you are authorized to use, and disconnect ones you no longer need.
  • Review actions that ask for your approval before you approve them, especially anything involving money, customers, or public channels.
  • Keep the email address you use to sign in secure, since it can be used to recover account access.
  • Connect tools through their official authorization flow rather than pasting long-lived secrets into chat.
07

Reporting a vulnerability

If you believe you have found a security issue, please email support@ceocrew.app. We welcome responsible disclosure and will work with you to confirm and address valid reports.

Home·About·Privacy·Terms·Cookies·Security© 2026 CeoCrew