Security Policy

Last Updated: 6/22/26

Introduction

As a security firm, we are deeply committed to security and privacy. Our goal is to give you the information you need to feel confident in our ability to provide a secure platform. Our program combines the governance and technical controls that keep the information we handle secure and continuously monitored.

We have adopted a set of policies aligned to NIST 800-53 and the NIST Cybersecurity Framework to build a comprehensive security program. The list below outlines that program and its features, followed by a summary of each area.

The list below outlines our security program and features.  A summary of our program and corresponding policies follows below.

  1. User access is protected through strong authentication.

  2. Internal system access is controlled through least-privilege and multi-factor authentication (MFA).

  3. System access is logged and audited.

  4. Data is encrypted in transit and at rest.

  5. A front-end firewall and intrusion detection block unauthorized traffic.

  6. A tested Business Continuity Plan is maintained.

  7. Third-party vendors and contractors are fully vetted.

  8. Customer data is logically separated.

  9. A comprehensive security training program covers all employees.

  10. Software development and change management follow security-focused processes

  11. An incident response training and readiness program is in place.

  12. Systems are patched consistently and reviewed for vulnerabilities.

  13. A risk assessment is performed annually.

  14. Network vulnerability scans are performed quarterly.

Security Program Details

Our security policy sets out our position on a range of security topics. Executive leadership is accountable for the program, but the entire company works to keep the security of our customers first. These policies reflect our commitment to providing a trusted solution.

Alignment with NIST 800-53

We align our information security program to the NIST 800-53 framework and the NIST Cybersecurity Framework (CSF) 2.0. Maturing the program is driven by alignment to these frameworks and an understanding of potential and evolving threats.

Security Training

Security training is mandatory for all employees. It is structured to teach our Information Security and Privacy policies, build an understanding of security in the context of our service and industry, instill a commitment to protecting our customers, and above all, ensure the safety and security of customer data.

Application Security

Application security is of the utmost importance. With applications running in the cloud, our cloud provider is responsible for infrastructure-level security; under the shared responsibility model, we are responsible for our application security. To follow best practices, we train on the OWASP Top 10 and conduct both internal and external code reviews focused on security.

Data Encryption

All data in transit is secured with TLS. Systems are configured to require modern TLS, meeting industry standards for externally facing systems. You can view an up-to-date assessment of our TLS configuration with the SSL Labs SSL Test.

Data at rest is protected with symmetric encryption (AES-256), ensuring it is viewable only by authorized users.

Data Access and Handling

Our environment is highly restricted by design. Access controls ensure data is available only to appropriate parties. Internally, employees may be granted access to our platform for administration purposes only. All data is encrypted in transit and at rest within our systems.

Questions

Contact our security team at security[at]cruxsecurity.ai.