Skip to main content
CrowdSafe Group™CrowdSafeData℠by CrowdSafe Group™
TermsPrivacyDPARetentionSecurityStatus
Trust center

Security and incident response

CrowdSafeData uses layered controls for identity, tenant isolation, ingestion integrity, auditability and recoverability.

Effective August 16, 2026 · Version 1.1

Security architecture

Identity

Google or verified-email authentication through Firebase, followed by short-lived, signed, HttpOnly CrowdSafeData sessions.

Authorization

Organization-scoped records with owner, administrator, analyst and viewer roles.

Ingestion

Allowed formats, bounded-memory transfer parts, daily and storage limits, secure filenames, streaming server verification and SHA-256 manifests.

Storage

Structured records in tenant-scoped database tables and source objects in protected object storage.

Evidence integrity

Audit events, explicit mapping confidence and protected analytical limits.

Application controls

Security headers, no-store responses, input validation and signed billing webhooks.

Continuity

Versioned recovery snapshots with integrity hashes and a documented retention schedule.

Monitoring

Deep health checks, hosted runtime logs, request diagnostics and a public service-status surface.

Incident response process

  1. Triage: validate the report, affected organization, time window and data category.
  2. Contain: restrict affected access, preserve evidence and limit further exposure.
  3. Assess: determine scope, root cause, legal obligations and operational impact.
  4. Notify: contact affected customers without undue delay when a confirmed incident requires notice.
  5. Recover: restore validated service state, monitor recurrence and document decisions.
  6. Improve: complete a post-incident review and track corrective actions.

Reporting a concern

Open a Security case through the Account and Support console. Include the organization, time observed, affected feature, evidence available and a safe callback method. Do not include passwords, secret keys or unnecessary personal data. CrowdSafeData support is not an emergency dispatch channel.

Service providers

Core service providers are disclosed in the Privacy Policy and DPA. OpenAI Sites and Cloudflare services support site delivery, the hosted runtime and protected storage. Google Firebase provides authentication. PayPal or Stripe processes billing only when the applicable method is activated.

Responsible testing

Do not perform disruptive testing, social engineering, denial-of-service activity, automated account creation or access to another organization. Report suspected vulnerabilities through the Security support category so written authorization and a safe testing scope can be established.

CrowdSafeData is a CrowdSafe Group product. © 2026 THE CROWDSAFE GROUP, LLC. All rights reserved.Account and support