Security & Data Protection
Your data, in an instance of its own.
Every client runs on a dedicated CrownEvents.OS instance: its own database, its own private file storage, its own address. Here’s how it’s built, how it’s protected, and what happens to your data from the first day to the last.
0client
Per instance, with its own database, file storage and address
UShosted
On Vercel and Supabase, both SOC 2 Type II–audited
Dailybackups
Encrypted at rest and in transit
0hours
To notify you, should a breach of your data ever be confirmed
Architecture
Isolated by design, not by permission settings
Most business software keeps every customer in one shared database and relies on permissions to keep their records apart. CrownEvents.OS doesn’t. Each client gets a complete, separate set of infrastructure, and none of it is shared.
01
Its own database
A dedicated Postgres database, provisioned for your organization alone. Your records never sit in a shared system, partitioned off from anyone else’s.
02
Its own private file storage
Contracts, proposals and documents live in a private storage bucket. Every download checks that the person asking is a signed-in member of your organization.
03
Its own address
Your instance runs on its own subdomain of northcrowngroup.com, and that address is the only public way in.
Everything runs in the United States, hosted on SOC 2 Type II–audited infrastructure (Vercel, Supabase). Nothing is shared between clients: no shared database, no cross-client analytics, no pooled data.
Controls
Protected at every layer
The same controls in every instance, maintained by us, with nothing for your team to configure or remember.
Access
Who can get in, and what they can do once they’re there.
- Named logins
- Everyone has their own login, and logins are never shared. Every user accepts the platform’s terms of use before first use.
- Your people only
- Invitations work only at your organization’s email domains. Anyone else needs your written confirmation that they’re bound by confidentiality.
- Roles
- Owner, Admin, Member and read-only Viewer, enforced on every change.
- Sessions
- Sign-ins expire automatically and are limited per person. Removing someone ends their sessions immediately.
- Sign-in protection
- Repeated failed sign-in attempts lock the account temporarily.
- Our own access
- A single, clearly labelled NorthCrown Support account, disclosed in your agreement, so we can resolve what you raise.
Data
How your records are protected, kept and traced.
- Encryption
- At rest (AES-256) and in transit (TLS).
- Backups
- Daily, retained for seven days.
- Activity log
- Sign-in attempts, team changes and exports are recorded.
- Traceable exports
- Every export is watermarked and carries a unique trace code, so any document can be traced to who exported it, and when.
- Maintenance
- Security patches and platform updates are applied for you. There’s nothing for your IT team to install.
- Breach notification
- Within 72 hours of a confirmed breach of your data.
Data Lifecycle
From the first day to the last
Your data is yours; the platform and methodology are ours. Here’s the schedule both follow, written into every agreement: no data held hostage, and none kept forever.
From go-live
Active term
Your data lives only in your instance and is backed up daily. Your team exports reports whenever it needs to, and a full export of your raw data is available on request.
End of term, or termination
Subscription ends
The platform stops accepting changes and your export window opens. Nothing has been deleted.
30 days
Export window
Request a full export of your data (events, tasks, timelines, budgets, vendors, ROI data and documents) in standard formats. It covers your data; the platform’s templates and methodology stay with NorthCrown.
After the window closes
Permanent deletion
Your instance, its database, file storage and backups are permanently deleted within 30 days, and you receive a certificate of deletion. Nothing is archived or held in escrow.
Subprocessors
The providers behind your instance
A short list, disclosed in full in your agreement. Each one processes client data only to provide its part of the service.
| Provider | What it does | Notes |
|---|---|---|
| Vercel | Application hosting | US region |
| Supabase (on AWS) | Database and file storage | US region, with a separate project for every client |
| Resend | Email delivery | Invitations, notifications and support messages |
| Anthropic | AI-assisted features | Can be switched off for your instance; data sent through its API isn’t used to train models |
| Optional sign-in, maps and geocoding | Only when those features are used | |
| Stripe | Billing | Only once card billing is enabled, and it handles billing data only |
What we never do with your data
Sell, rent or trade your data, to anyone, for any purpose
Share it with other clients, or pool it for cross-client analytics
Use it to train AI models, ours or anyone else’s
Use it for anything other than running your instance
Keep it past the deletion date: no archives, no escrow
Security Reviews
Completing a vendor security review?
We’re glad to walk your IT or security team through any of this in detail. Uptime targets, backup and recovery objectives, and the full subprocessor terms are written into your agreement’s hosting, security and data protection schedule.
