Menu

SECURITY / TRUST

Trust starts with controls we can explain.

True Crew treats tenant boundaries, privileged access, deployment discipline, and maintenance as product requirements—not afterthoughts.

01

Tenant-aware access

Customer product data is designed around tenant-scoped authorization and database access policies rather than shared, unbounded application reads.

02

Privileged credentials stay server-side

Service credentials and other privileged integration secrets are kept out of browser code and public configuration.

03

Preview before production

Material changes are validated on isolated branches and preview deployments before production promotion or domain changes.

04

Dependency and secret hygiene

The engineering baseline includes dependency review, pinned build inputs, secret scanning, and source-controlled security checks.

OUR STANDARD

Clear claims. Controlled changes. No security theater.

We would rather describe the controls that exist today than imply a certification, audit result, or guarantee that does not exist.

We do not publish certifications or compliance claims that have not been earned.
Production DNS, email, authentication, and data-boundary changes require deliberate promotion steps.
Public lead capture uses bounded validation and keeps privileged database access off the client.
Security guidance and maintenance expectations live with the source code so they can be reviewed with changes.

SECURITY QUESTIONS

Need to understand a control before you evaluate a product?

Talk to True Crew