Trust & Security
Built for the buyers who ask hard questions.
Crescive is a business SaaS product handling your brand's competitive intelligence. Here is exactly how that data is protected — no vague assurances, just the controls that are in place.
Tenant isolation
LiveEvery customer table is protected by Postgres row-level security. A workspace can only ever read its own rows — enforced at the database, not just the app.
Least-privilege access
LiveThe browser only ever holds an anon key scoped by RLS. The service-role key is server-only and never shipped to the client.
Role-based access control
LiveOwner, admin, member, and viewer roles gate every mutation. Privileged actions require owner/admin, and a workspace can never be left without an owner.
Audit logging
LiveBudget changes, brand-setting changes, team membership, and published fixes are recorded to a tamper-evident audit log visible in-app.
Privacy by design
LiveWe store no PII beyond your login email. IP addresses are hashed with a rotating daily salt, never stored raw. Your data is never used to train models.
Official APIs only
LiveCrescive reads answer engines through official provider APIs — no scraping, no ToS or CFAA exposure. Crawler traffic is verified against published IP ranges.
Single sign-on (SSO)
AvailableSAML SSO is available for enterprise workspaces via your identity provider (Okta, Entra ID, Google Workspace).
SOC 2 Type II
In progressThe controls above form the control base for SOC 2. Type II examination is on the roadmap; the trust surface it depends on is already built.
Reporting a vulnerability
Found something? Email [email protected]. We respond within one business day and credit responsible disclosure.
Talk to us about enterprise