CREWBEAM / SECURITY
Security, with clear boundaries
Customer records belong behind controlled access. The public marketing website is separate from the CrewBeam application.
A separate public website
The website serves static pages from its own Firebase Hosting project. It contains no application login session, customer database connection or administrative interface.
Application access design
CrewBeam uses individual identities and company membership checks. Role-sensitive commands are checked on the server. Private file downloads require authorization. These describe implementation choices, not an independent certification or guarantee.
Current readiness
Device testing and release verification remain separate from backend tests. No SOC 2, ISO 27001, HIPAA or other compliance certification is claimed. Live payment collection is not offered.
Reporting a concern
A dedicated public security contact has not yet been confirmed. Do not place vulnerability details, passwords or customer data in public comments or in the request-preparation form. This page will be updated when a private reporting channel is available.
Updated September 29, 2026.