Our commitment to protecting your data
CrowdAI is committed to maintaining the highest standards of security to protect our systems and your data. We employ a multi-layered security approach, covering infrastructure, application, and organizational practices. This statement outlines our key security measures.
Our Service is hosted on enterprise-grade, leading cloud infrastructure providers that are certified for SOC 2, ISO 27001, and other global security standards. Physical access to data centers is strictly controlled.
All data is encrypted both in transit and at rest. We enforce TLS 1.2 or higher for all data transmitted over the internet. Data at rest in our databases, caches, and storage is encrypted using industry-standard AES-256 encryption.
Our production environment is logically isolated from all other environments, including development and staging. Network access between servers is restricted by strict firewall rules, following the principle of least privilege.
We aggregate and monitor logs from our infrastructure and applications to detect and respond to security events. Automated alerting is in place for suspicious activities, unauthorized access attempts, and system anomalies.
We follow secure coding practices and integrate security into our software development lifecycle. This includes code reviews, dependency scanning, and static analysis to identify potential vulnerabilities before they reach production.
User authentication is handled via secure OAuth 2.0 protocols with trusted providers like Google. Access to data within our systems is strictly governed by role-based access control (RBAC), ensuring that employees can only access data required for their job function.
We conduct regular vulnerability scans of our applications and infrastructure. For critical systems, we engage third-party security firms to perform penetration tests to identify and remediate security weaknesses.
Our infrastructure providers are certified for SOC 2, ISO 27001, PCI DSS, and HIPAA. We are actively working towards achieving our own SOC 2 Type II and ISO 27001 certifications to formally attest to our security controls.
For our Enterprise customers, we provide detailed audit logs that record important events within your account. This includes user logins, changes to settings, workflow creation and execution, and user management activities. These logs are available for export and integration with your internal SIEM tools.
All internal access to production systems is logged and monitored. We enforce the principle of least privilege, and access is reviewed on a regular basis. Customer data is only accessed by authorized personnel for troubleshooting and support purposes, with customer consent.
While we ensure that data transmission to Third-Party AI Model providers is encrypted, we do not control their internal security practices. We select reputable providers who publish their own security and compliance documentation. However, you acknowledge that the ultimate security of your User Content, once transmitted, is subject to the security measures of the respective third-party provider.
Your security is a shared responsibility. You are responsible for:
If you believe you have discovered a security vulnerability in our Service, please notify us immediately at info@crowdai.io. We are committed to working with the security community to resolve verified vulnerabilities. Please do not publicly disclose any issue until we have had a reasonable time to address it.
Cookies on CrowdAI
We use essential cookies to sign you in and remember preferences. With your permission, we also use Google Analytics to understand how the site is used. See our Cookie Policy and Privacy Policy.