Security & trust

Your data is yours. We mean that literally.

Crewly reads from Slack, talks to language models, and remembers what your team tells it. Here is exactly how we handle each of those, what we promise, and what we have not built yet.

No model training on your data

Crewly is designed to use providers with no-train terms for workspace traffic. Provider policy still depends on the model route and any bring-your-own-key setting your workspace chooses.

Encrypted Slack tokens

Your workspace access token is encrypted at rest, decrypted only in memory for the request that needs it, and never written to logs, traces, or analytics. If our logs leak, your token does not.

Tenant isolation by default

Workspace data is scoped at the application and database layers with row-level security on the core tables. We continue to test this boundary as new delivery tables are added.

Crewly only speaks when spoken to

It responds to @mentions and the channels you pick. It does not read channels it was not invited to, and it does not act on its own. You choose where it lives, and you can remove it in one click.

The specifics

What we promise, point by point.

Export anytime

Your memory exports as portable Markdown + JSON. No proprietary format, no lock-in. If we ever shut down, you walk away with everything.

Delete means delete

Remove a memory or close your account and it is deleted from primary storage. Backup purge timing is handled through support while the self-serve retention tooling is finished.

Least-privilege Slack scopes

We request only the OAuth scopes the active skills need — nothing speculative. You can review the full list before you install.

Encryption in transit and at rest

TLS in transit. Secrets and tokens are encrypted at rest. Database access is scoped by workspace.

Hosted in the US

Data lives in US-region Postgres (Neon) and US compute (Railway). Sub-processors: Anthropic, Voyage, Clerk, Stripe, Sentry.

Honest status — what we have not built yet.

Crewly is not SOC 2 certified yet. SSO / SCIM, audit-log export, and a standard DPA are Company-track requirements. If your review needs any of these today, email us and we will give you the real status.

Security question we did not answer?