Crewmojo Security

Crewmojo's primary security objective is safeguarding our customers' data.

Robust platform & governance for enterprise.

Our security approach focuses on governance, risk management and compliance. This includes standards-based best practices like encryption, independent testing and continuous monitoring.

Encryption at rest & in transit

Independent penetration testing

Administrative access control

System monitoring & logging

Alerting

Employee training & awareness

Security Compliance.

Crewmojo has implemented a comprehensive Information Security Management System to safeguard the security and privacy of customer data. We perform regular vulnerability scans and engage an independent security firm for penetration testing at least annually.

SOC 2 Type 2

Independently audited and certified against SOC 2 Type 2 trust service criteria.

GDPR

Aligned with GDPR requirements for the handling of personal data.

World-class infrastructure.

Crewmojo hosts our test and production environments on Amazon's AWS platform. AWS data centres are housed in nondescript facilities, with robust perimeter control. Physical access is strictly controlled both at the perimeter and at building ingress points by professional security staff utilising video surveillance, state-of-the-art intrusion detection systems, and other electronic means. AWS data centres are SOC 1, SOC 2, and SOC 3 certified.

Certified data centres

Amazon AWSSOC 1SOC 2SOC 3

Strong application security.

Data is encrypted in transit with industry-standard TLS connections and at rest with 256-bit AES encryption. Application development is in line with our Secure Coding Policy with security considered from the design stage right through to deployment and testing.

Application safeguards

TLS in transit

256-bit AES at rest

Two-factor authentication

Role-based admin access

35

Day rolling recovery

Backup and resilience.

Crewmojo ensures data is replicated and backed up in multiple durable data-stores. Data is configured with a rolling 35-day point-in-time recovery strategy. Data is also replicated across availability zones and infrastructure locations in order to provide fault-tolerance as well as scalability and responsive recovery, when necessary.

Questions about how we keep your data safe?

Get in touch and we'll walk you through our security practices in more detail.