Skip to content

Trust & Security

Built for the buyers who ask hard questions.

Crescive is a business SaaS product handling your brand's competitive intelligence. Here is exactly how that data is protected — no vague assurances, just the controls that are in place.

Tenant isolation

Live

Every customer table is protected by Postgres row-level security. A workspace can only ever read its own rows — enforced at the database, not just the app.

Least-privilege access

Live

The browser only ever holds an anon key scoped by RLS. The service-role key is server-only and never shipped to the client.

Role-based access control

Live

Owner, admin, member, and viewer roles gate every mutation. Privileged actions require owner/admin, and a workspace can never be left without an owner.

Audit logging

Live

Budget changes, brand-setting changes, team membership, and published fixes are recorded to a tamper-evident audit log visible in-app.

Privacy by design

Live

We store no PII beyond your login email. IP addresses are hashed with a rotating daily salt, never stored raw. Your data is never used to train models.

Official APIs only

Live

Crescive reads answer engines through official provider APIs — no scraping, no ToS or CFAA exposure. Crawler traffic is verified against published IP ranges.

Single sign-on (SSO)

Available

SAML SSO is available for enterprise workspaces via your identity provider (Okta, Entra ID, Google Workspace).

SOC 2 Type II

In progress

The controls above form the control base for SOC 2. Type II examination is on the roadmap; the trust surface it depends on is already built.

Reporting a vulnerability

Found something? Email [email protected]. We respond within one business day and credit responsible disclosure.

Talk to us about enterprise