Security and trust

Crestlio handles highly sensitive employment information. Controls are built into the data model, not layered on afterwards.

This page is maintained by the app owner and describes controls that are actually enabled in this application. It is not an independent audit, certification, or attestation. Read the privacy notice for data handling, retention, and individual rights.

Tenant isolation

  • Every tenant-owned record carries an organization ID
  • Row-level security enforced in the database, not only in the interface
  • Authorization checked at the API and database layers
  • No tenant can read another tenant's data

Record integrity

  • Append-only audit events with actor, action, values, reason, and address
  • Employee responses can never be deleted by managers or HR
  • Amendments preserve prior versions and require a written reason
  • Acknowledgment stores the exact wording displayed at the time

Privacy by design

  • Email notifications carry no names, references, or performance details
  • Internal-only fields are separated from employee-visible content
  • Reviewer access is explicitly granted, scoped, and time-limited
  • Exports and downloads are logged

Governance readiness

  • Configurable retention and legal holds that block deletion
  • Designed with SOC 2-aligned security principles and ISO/IEC 27001 principles in mind
  • Designed with WCAG 2.2 Level AA accessibility principles; status is never conveyed by color alone
  • No certification, attestation, or independent assessment is claimed

AI governance

  • AI features produce suggestions and writing guidance only, never decisions
  • Employment, disciplinary, and termination outcomes are decided and recorded by people
  • AI-assisted content is human-reviewed before it reaches an employee
  • Crestlio is decision support, not an autonomous employment decision-maker

Account security

  • Anonymous sign-in is disabled; every session is tied to a verified account
  • New email accounts must confirm their address before the session is usable
  • Passwords are checked against known-breached credential lists at sign-up and change
  • Google sign-in is available for organizations that centralize identity

Least privilege by default

  • Anonymous callers have no read or write reach into any tenant table
  • Internal authorization helpers are executable only by signed-in sessions
  • The fictional demo tenant is strictly read-only; writes require real membership
  • Audit events and employee responses cannot be updated or deleted at the privilege level

Data minimization

  • No field exists for special-category data such as health or biometric information
  • Customer content is never sold, used for advertising, or used to train models
  • No score, ranking, or automated employment decision is produced about any person
  • Retention periods and lawful basis are recorded per record type, per tenant

Shared responsibility

  • • Platform: hosting, managed database, encrypted transport and storage at rest, authentication, and row-level security enforcement.
  • • App owner: access reviews, retention and legal-hold configuration, sub-processor disclosures, the data processing agreement, and incident notification.
  • • Customer: keeping its people directory accurate, granting the minimum roles needed, and not entering special-category data into free-text fields.

Frameworks such as SOC 2, ISO/IEC 27001, GDPR, HIPAA, and CCPA depend on organizational processes as well as software controls. Using Crestlio does not by itself make an organization legally compliant. Request the app owner's current documentation before relying on any framework statement.

Assurance

This is the complete and current list of independent assurance covering Crestlio.

  • SOC 2 Type INot attested

    Not attested. The platform is designed with controls commonly evaluated under the AICPA Trust Services Criteria.

  • SOC 2 Type IINot attested

    Not attested. No report exists and none is offered on request.

  • ISO/IEC 27001Not attested

    Not certified. Security controls are informed by recognized information security frameworks, including ISO/IEC 27001 principles.

  • Independent penetration testNot attested

    Not completed. No third-party assessment result is represented anywhere on this site.

  • WCAG 2.2 Level AAInternal review

    Internal review. The interface is designed with WCAG 2.2 Level AA principles in mind and reviewed internally. No independent assessment or certificate is claimed.

  • HIPAA

    No certification exists for HIPAA. Crestlio does not currently offer a business associate agreement. Organizations with healthcare-specific requirements should contact Crestlio to discuss their security, privacy, and contractual requirements.

  • PCI DSS

    Crestlio does not store, process, or transmit raw payment card data. Any payment handling is performed by a third-party payment processor.

What we do not claim

  • No SOC 2 or ISO/IEC 27001 certification or attestation is claimed.
  • No independent penetration-test result is represented as completed.
  • No third-party accessibility certification is claimed.
  • No customer counts, usage volumes, uptime percentages, or performance guarantees are published, because no independently supportable operating history exists yet.
  • Compliance with legal and regulatory requirements also depends on each customer's configuration, policies, processes, and use of Crestlio.