At a glance
Summary
Web authentication
Passkeys, TOTP, email OTP, backup codes and second-factor lockout controls are supported by the web authentication service.
Native devices
Crewzon may offer passkeys and local device authentication on supported devices and builds.
Deployment
Rate limiting, uploads, monitoring and provider controls depend on the relevant configuration.
Report an issue
Send responsible security disclosures to security@crewzon.com.
OverviewTap to collapse
Crewzon uses technical and organisational measures intended to protect the service and the information it handles. Security depends on Crewzon, its service providers, customer configuration, user behaviour and the devices and networks used to access the service. No internet-connected service can guarantee absolute security.
1. Account AuthenticationTap to collapse
Crewzon's web authentication supports:
- passkeys, with user verification required by the authenticator;
- time-based one-time passwords through an authenticator app;
- one-time codes sent by email as a second-factor option;
- single-use backup codes for account recovery; and
- temporary lockout controls after repeated failed second-factor attempts.
The availability of an authentication method may depend on the account, browser, device, operating system and service configuration. When password sign-in is used, the authentication service processes and stores password credentials in hashed form rather than as readable passwords. Authenticated access uses managed sessions, and server-side checks require a valid user and Business Account before protected workspace data is returned.
Passkey private keys remain with the user's authenticator and are not received by Crewzon.
2. Native App and Device AuthenticationTap to collapse
On supported devices and builds, Crewzon may offer passkey sign-in and a local app lock. These controls depend on the operating system, device capability, installed build and configuration.
On supported devices and builds, the operating system may use Face ID, Touch ID, Android biometrics or a device passcode to unlock a passkey or local app lock. Crewzon does not receive the user's fingerprint, face image, biometric template, device passcode or passkey private key.
Users should keep their devices updated, use a device screen lock and remove Crewzon access from lost, shared or retired devices.
3. Access and Data ProtectionTap to collapse
Crewzon's current web application includes:
- role and Business Account checks intended to keep workspace access within the correct tenant;
- HTTPS/TLS for supported public web traffic;
- browser security headers, including content-security, frame, content-type, referrer, permissions and transport-security policies;
- validation of supported attachment types and declared file size before a presigned upload is authorised; and
- restricted storage keys and authenticated server checks when uploaded job records are created.
Some protections depend on deployment configuration. Distributed rate limiting uses Upstash Redis only where the required environment variables are configured. File uploads depend on configured Cloudflare R2 storage. Error monitoring and release reporting depend on configured Sentry credentials. Email, SMS, push, payment and other integrations have their own provider and configuration dependencies.
4. Monitoring and Incident ResponseTap to collapse
Crewzon records operational, authentication and application information needed to run, troubleshoot and protect the service. Where monitoring is configured, alerts and diagnostic reports help identify errors and unusual conditions.
Crewzon will take reasonable steps to assess, contain and remediate suspected security incidents according to the circumstances and available evidence. Crewzon handles notifications under applicable law and the Data Processing Addendum. Security controls and incident handling are reviewed as the service changes.
5. Customer ResponsibilitiesTap to collapse
Business Accounts and users are responsible for:
- using unique credentials and protecting access to email and authenticator accounts;
- storing backup and recovery codes securely and separately from the device used to sign in;
- not sharing passkeys, one-time codes, backup codes or active sessions;
- assigning the least access each user needs and promptly removing former staff and contractors;
- checking account and workspace activity and reporting suspected unauthorised access promptly; and
- securing devices, browsers, networks, integrations and exported data outside Crewzon.
Crewzon will never ask a user to send a password, one-time code, backup code or passkey private key by email or support message.
6. Responsible DisclosureTap to collapse
Send suspected vulnerabilities or unauthorised-access reports to security@crewzon.com. Include enough detail to reproduce or investigate the issue, avoid accessing or changing other people's data, and do not disrupt the service. Crewzon will acknowledge and assess reports as operational capacity permits.
This page describes current and feature-dependent safeguards. It is not a certification, audit report or guarantee that every control is available in every build or deployment.