Security
How we keep your data safe
A short, factual list of what's built into Crew & Level today. No badges we haven't earned.
Each company's data is kept apart
Every record belongs to one company and every request is checked against the company it's made for, in the web app, the tech app, the API and AI app connections alike. Technicians see only the jobs they're assigned to and what hangs off them.
Passwords and tokens are never stored as-is
Passwords are stored as salted scrypt hashes. Session tokens, API keys and one-time links (invites, password resets, customer links) are stored only as hashes, so a copy of the database doesn't hand out working credentials.
Secrets encrypted at rest
Connection tokens for QuickBooks and the secrets behind two-step sign-in are encrypted with AES-256-GCM; two-step recovery codes are stored as keyed hashes. The service won't start in production without its encryption and signing keys.
Two-step sign-in
Anyone can add a code from an authenticator app to their password sign-in, with single-use recovery codes. Owners and admins can require it for the whole company and reset it for someone who lost their phone. Google and Microsoft sign-ins use that account's own security.
Sessions you control
Sign-in uses one HttpOnly, SameSite cookie, sent only over HTTPS, that lasts 30 days. You can see where you're signed in and sign out any device or everywhere else; owners and admins can sign a team member out everywhere; a password reset signs out every other session. Writes are protected against cross-site request forgery.
Roles and scoped API keys
Owner, admin, dispatcher, CSR and technician roles use the same permission scopes as API keys. Keys can be limited to what an integration needs, set to expire (with a warning a week before) and revoked.
An audit trail of every change
Every change is recorded as an event naming who made it: a person, an API key or integration, an AI agent, the system, or a customer. Webhooks you set up are signed (HMAC-SHA256) so you can check they came from us.
Rate limits
Sign-in, two-step codes, password resets, online booking, customer links and the AI features are rate-limited across every server.
Card details never touch our servers
Customers pay on Stripe's hosted checkout. We record the payment, never the card number.
Less data, kept for less time
Technician location is only collected while they're clocked in or heading to a job, and location history is deleted after 30 days. This site counts visits without cookies or personal data (and not at all with Do Not Track or Global Privacy Control), has no ads or tracking scripts, and business websites we host run no scripts at all.
Report a problem
Found a security issue? Email security@crewandlevel.com with what you found and how to reproduce it. Please give us a reasonable time to fix it before telling anyone else, and don't access other people's data while testing.
More detail on what data we hold and who processes it: privacy policy and subprocessors.