Founding offer: save 20% for life, only 50 places·14-day free trialClaim yours →

Security & data

Your team’s data, kept apart and kept safe.

Security is built into how Crewqo is put together, not added on top. Here is exactly how it works, in plain words.

LiveHow a request finds its workspace
Lucas · Halden Studio teamhalden.crewqo.app Nike · Halden’s client portalportal.halden.studio Maya · Brightline Media teambrightline.crewqo.app Crewqoreads the address,opens one workspace H Halden Studiohalden.crewqo.app workspace.dbHalden’s data onlyits own file, its own backups B Brightline Mediabrightline.crewqo.app workspace.dbBrightline’s data onlyits own file, its own backups ✕ No way across halden.crewqo.app portal.halden.studio brightline.crewqo.app Crewqoreads the address H Halden Studio workspace.db B Brightline workspace.db ✕ No way across

Demo workspace. Nike, Zara and H&M appear as example client names only; they are not Crewqo customers and their names belong to their owners.

01

A separate database for every agency.

Every agency gets its own workspace, web address and database file. Crewqo reads the address you visit and opens that workspace, and only that one. One agency can never see another’s data.

  • Own database file. Not a shared table with an “agency” column. A separate file per agency.
  • Chosen by address. Your Crewqo address, or your own domain for the client portal.
  • Sign-ins stay home. A sign-in only works in the workspace it was made in.

02

Files stay in storage you own. Any storage.

Files your team and clients share go straight into the storage you connect, not onto our servers: Google Drive, OneDrive or SharePoint, Dropbox, any S3-compatible bucket (Amazon S3, Cloudflare R2, Backblaze B2, Wasabi and more), or your own office server (Nextcloud, Synology, QNAP).

  • Streamed straight through. A big video passes through Crewqo on its way to your storage. No permanent copy is kept on our servers; a short playback cache clears itself.
  • Checked before it’s used. When you connect storage, Crewqo writes a test file, reads it back and deletes it, then keeps checking every day and warns you if something breaks.
  • Split it your way. Keep documents in Google Drive and send heavy video to cheaper bulk storage.
  • Leave any time. Your files are already in your storage, in plain folders you can browse, so there’s nothing to move out.

03

Scrambled where it matters.

Passwords can’t be read back by anyone, keys for the tools you connect are locked before they are saved, and every connection is encrypted.

PasswordsHashed with bcrypt, one way. We store the scrambled result, never the password itself.
sunflower-lisbon-42→
Keys for the tools you connectAI, email and other connection keys are encrypted with AES-256-GCM before they are saved, and only unlocked when Crewqo uses them for you.
Your OpenAI key→
Every connectionHTTPS everywhere, with HSTS so browsers never fall back to an unencrypted connection. Other websites can’t show Crewqo inside a frame.
halden.crewqo.app→

04

Backed up every night. Locked with your key.

Everything you do in Crewqo (tasks, messages, clients, invoices) is backed up every night, encrypted, and kept for 30 days. A copy also goes to your own storage.

  • Your key, not ours. Turn on your backup key and the key that opens your backups is downloaded to you once. We keep only the lock, so we can’t open them.
  • Tamper-proof. Each backup is encrypted with AES-256-GCM in sealed chunks, so a changed or cut-short file is refused, not restored.
  • Restore it yourself. Upload a backup with your key file and your workspace is back as it was.
  • Keep the key safe. Without it nobody can open those backups, including us. Your live workspace isn’t affected if you lose it.
Every workspace, every nightEach agency’s database is copied on its own, one after another, every night.
Trash for 30 daysDeleted a client, project, task, lead or invoice? Owners can restore it from Trash.
Files aren’t in these backupsThey were never on our servers. They live in your own storage.
Export any timeDownload everything in your workspace in one click.

05

See every device. Sign any of them out.

Owners see who is signed in, from where and on what, and can end a session with one click.

  • One device at a time. Signing in somewhere new ends that person’s old session.
  • Fresh each workday. Sessions end after 12 hours, so everyone signs in again the next day.
  • Every sign-in recorded. Device, browser and approximate location, kept for the owner.
Signed-in devicesSettings › Sessions · Halden Studio
4 active
LM
Lucas MeyerVideo editor
Chrome · macOSLisbon, Portugal
Active now
SA
Sofia AlvarezDesigner
Safari · iPhoneBerlin, Germany
4 min ago
MC
Maya ChenDesign lead
Chrome · WindowsSingapore
12 min ago
JC
James CarterDeveloper
Firefox · LinuxToronto, Canada
1 hour ago

Try it: sign someone out.

06

Everyone sees only what they need.

Access is given by area, never page by page. Owners have everything, clients only ever see their own portal, and you decide the rest. Try the switches.

AreaOwnerManagerTeam memberClientTheir own portal only
Their own workMy Day, own tasks, time, leave, chat, docsAlwaysAlwaysAlways—
Clients & projectsClients, projects, deliverables, contactsAlwaysAlways—
Team workTask board, files, weekly output, workloadAlwaysAlways—
SalesLeads, proposals, contracts, services, formsAlways—
FinanceRevenue, invoices, expenses, accountsAlways—
HRAttendance, leave, salaries, hiring, performanceAlways—
Business overviewRevenue, leads and team numbersAlways—
Workspace settingsTeam members, connections, securityAlways———

AlwaysYou choose, per person— Never

The AI assistant follows the same rules: it only receives what the person asking is allowed to see.

07

Sign-in that fights back.

Repeated wrong passwords lock the account for a while, and new devices are recorded.

  • Five strikes. Five wrong passwords lock the account for 15 minutes.
  • A code by email. When email is set up for your workspace, each sign-in also asks for a 6-digit code that expires after 10 minutes.
  • Guessing codes doesn’t work either. Five wrong codes and that code stops working.

08

The rest, in plain words.

Payments
Crewqo never sees card details. Subscriptions are processed by Polar, our merchant of record. Your clients pay you through your own Stripe or PayPal payment links, straight into your account.
AI
AI features use your own key with the provider you choose. The AI only receives what the person using it is allowed to see.
Browser protection
Crewqo pages send strict security headers: HTTPS only, no framing by other sites, and a content policy that limits where the page can load code and connect to.
Report a problem
Found a security issue? Please email support@crewqo.com and we will respond quickly.

Founding offer · first 50 agencies

Put your team in a workspace of its own

Its own database, files in your own storage, backups locked with your key. Start with a 14-day free trial, and the first 50 agencies save 20% for life.

14-day free trialNo card neededCancel any time