Security

Authorisation and money maths run on the server

CrewFlow holds cost rates, margins and billing details for multiple organisations. This is how that data is kept separated and how access is enforced. Every claim here reflects what is implemented today.

Practices

What's in place

Organisation isolation

Every record belongs to exactly one organisation. Queries are scoped to the caller's organisation, and an identifier from another organisation resolves to “not found” — a behaviour covered by automated tests on every entity.

Server-side authorisation

Every page, server action and API route re-checks the session, the organisation membership and the specific permission required. The interface only reflects what the server already enforces.

Role & permission model

Owner, Admin and Member, plus granular permissions. Financial figures — cost rates, profit, margin — are gated on a dedicated permission and are never included in the data sent to a browser that lacks it.

Server-side financial calculations

Revenue, cost, profit and margin are computed on the server from approved data. The client submits hours and expenses for approval; it cannot influence the resulting figures.

Billing integrity

Subscription state is synchronised from Stripe and every webhook is verified by signature before it is processed. The browser never controls plan or subscription status, and Stripe secret keys and identifiers never appear in client code.

Private file storage

Worker-document files are stored in a private bucket and served only through an authenticated route that re-checks permission and ownership. CrewFlow never generates a public file URL.

Authentication & sessions

Email-and-password authentication via Better Auth, with signed, HTTP-only session cookies. An optimistic cookie check gates protected routes; the authoritative check runs on the server against the database.

Opt-in, permission-gated AI

The AI features are optional. Each call runs on the server after the permission check and sends only the data the requesting user is already authorised to see.

Secret handling

No secret is committed to source control or exposed to the browser. Environment configuration is validated on boot, so a missing or malformed value fails fast rather than deep inside a request.

What we don't claim yet

Being straight about the gaps

CrewFlow is a young product. It does not have:

  • Formal certifications such as SOC 2 or ISO 27001, or a third-party penetration-test report
  • A contractual uptime or availability SLA
  • Single sign-on or two-factor authentication
  • A published infrastructure security whitepaper — hosting, database and backups are provided by our platform vendors

If you're evaluating CrewFlow for a security review, get in touch and we'll walk through the specifics of any of the above.