Security & trust

Your data is yours. We mean that literally.

Crewly reads from Slack, talks to language models, and remembers what your team tells it. Here is exactly how we handle each of those, what we promise, and what we have not built yet.

No model training on your data

We call Anthropic and Voyage APIs with no-train terms in place. Your messages and memory are never used to train a model — ours or theirs. This is contractual, not a setting you have to find.

Encrypted Slack tokens

Your workspace access token is encrypted at rest, decrypted only in memory for the request that needs it, and never written to logs, traces, or analytics. If our logs leak, your token does not.

Tenant isolation by default

Every row of every table is scoped to your organization with Postgres row-level security — enforced at the database, not just the app layer. One team can never read another team's memory, even through a bug.

Crewly only speaks when spoken to

It responds to @mentions and the channels you pick. It does not read channels it was not invited to, and it does not act on its own. You choose where it lives, and you can remove it in one click.

The specifics

What we promise, point by point.

Export anytime

Your memory exports as portable Markdown + JSON. No proprietary format, no lock-in. If we ever shut down, you walk away with everything.

Delete means delete

Remove a memory or close your account and it is purged from primary storage and queued out of backups. We do not keep shadow copies.

Least-privilege Slack scopes

We request only the OAuth scopes the active skills need — nothing speculative. You can review the full list before you install.

Encryption in transit and at rest

TLS everywhere. Secrets and tokens encrypted at rest. Database access scoped and audited.

Hosted in the US

Data lives in US-region Postgres (Neon) and US compute (Railway). Sub-processors: Anthropic, Voyage, Clerk, Stripe, Sentry.

Honest status — what we have not built yet.

SOC 2 Type II audit in progress — report expected Q3 2026. SSO / SCIM, audit-log export, and DPA available on the Company plan. If your security review needs any of these today, email us — we will tell you the real timeline, not a marketing one.

Security question we did not answer?