CrewHour

Security

Last updated: July 2, 2026

CrewHour exists to produce time records an employer can stand behind under scrutiny. That only works if the system holding those records is itself trustworthy, so this page describes the controls we actually run — and, just as plainly, the attestations we don't hold yet.

1. Record integrity — the core of the product

2. Tenant isolation

Each customer's data lives in its own PostgreSQL schema on infrastructure we operate — a query scoped to one tenant cannot read another tenant's rows by accident. Cross-tenant platform data (tenant registry, administrative accounts) is held separately.

3. Encryption and secrets

4. Access and authentication

5. Infrastructure and operations

6. What we don't claim (yet)

We would rather under-claim than over-claim — the whole product is built on that instinct.

7. Reporting a vulnerability

If you believe you've found a security issue, email info@crewhour.com with the details. We read every report, we won't pursue good-faith researchers, and we'll tell you what we did about it.