Compliance

Policies, notices and how we meet them

Crestlio holds some of the most sensitive records an employer keeps. Every policy below is authored and maintained by the app owner, and each one maps to a control that is actually enabled in the product rather than to an aspiration.

How each commitment is met in the product

  • Lawful basis and retention period are recorded per record type, per tenant, and enforced by a scheduled retention job
  • Access, correction and erasure requests are tracked end to end with due dates in Compliance → Data requests
  • Legal holds block automated purges until a release is approved by a legal reviewer
  • Every export is watermarked, hashed, signed and logged; audit-log exports require approval
  • Audit events and employee responses cannot be edited or deleted at the database privilege level
  • Incidents are triaged, assessed for notifiability, and evidenced through the incident workflow

What we do not claim

  • No SOC 2, ISO 27001, HIPAA or PCI certification is claimed or implied
  • No independent audit or penetration test result is published on this site
  • No accessibility conformance certificate has been issued by a third party
  • Compliance frameworks also depend on the customer's own organizational processes

Demonstration environment. All organization and people data shown in the product is fictional. Request the app owner’s current compliance documentation before relying on any framework claim.