NorthCrown Group

Security & Data Protection

Your data, in an instance of its own.

Every client runs on a dedicated CrownEvents.OS instance: its own database, its own private file storage, its own address. Here’s how it’s built, how it’s protected, and what happens to your data from the first day to the last.

  • 0client

    Per instance, with its own database, file storage and address

  • UShosted

    On Vercel and Supabase, both SOC 2 Type II–audited

  • Dailybackups

    Encrypted at rest and in transit

  • 0hours

    To notify you, should a breach of your data ever be confirmed

Architecture

Isolated by design, not by permission settings

Most business software keeps every customer in one shared database and relies on permissions to keep their records apart. CrownEvents.OS doesn’t. Each client gets a complete, separate set of infrastructure, and none of it is shared.

01

Its own database

A dedicated Postgres database, provisioned for your organization alone. Your records never sit in a shared system, partitioned off from anyone else’s.

02

Its own private file storage

Contracts, proposals and documents live in a private storage bucket. Every download checks that the person asking is a signed-in member of your organization.

03

Its own address

Your instance runs on its own subdomain of northcrowngroup.com, and that address is the only public way in.

Everything runs in the United States, hosted on SOC 2 Type II–audited infrastructure (Vercel, Supabase). Nothing is shared between clients: no shared database, no cross-client analytics, no pooled data.

Controls

Protected at every layer

The same controls in every instance, maintained by us, with nothing for your team to configure or remember.

Access

Who can get in, and what they can do once they’re there.

Named logins
Everyone has their own login, and logins are never shared. Every user accepts the platform’s terms of use before first use.
Your people only
Invitations work only at your organization’s email domains. Anyone else needs your written confirmation that they’re bound by confidentiality.
Roles
Owner, Admin, Member and read-only Viewer, enforced on every change.
Sessions
Sign-ins expire automatically and are limited per person. Removing someone ends their sessions immediately.
Sign-in protection
Repeated failed sign-in attempts lock the account temporarily.
Our own access
A single, clearly labelled NorthCrown Support account, disclosed in your agreement, so we can resolve what you raise.

Data

How your records are protected, kept and traced.

Encryption
At rest (AES-256) and in transit (TLS).
Backups
Daily, retained for seven days.
Activity log
Sign-in attempts, team changes and exports are recorded.
Traceable exports
Every export is watermarked and carries a unique trace code, so any document can be traced to who exported it, and when.
Maintenance
Security patches and platform updates are applied for you. There’s nothing for your IT team to install.
Breach notification
Within 72 hours of a confirmed breach of your data.

Data Lifecycle

From the first day to the last

Your data is yours; the platform and methodology are ours. Here’s the schedule both follow, written into every agreement: no data held hostage, and none kept forever.

  1. From go-live

    Active term

    Your data lives only in your instance and is backed up daily. Your team exports reports whenever it needs to, and a full export of your raw data is available on request.

  2. End of term, or termination

    Subscription ends

    The platform stops accepting changes and your export window opens. Nothing has been deleted.

  3. 30 days

    Export window

    Request a full export of your data (events, tasks, timelines, budgets, vendors, ROI data and documents) in standard formats. It covers your data; the platform’s templates and methodology stay with NorthCrown.

  4. After the window closes

    Permanent deletion

    Your instance, its database, file storage and backups are permanently deleted within 30 days, and you receive a certificate of deletion. Nothing is archived or held in escrow.

Subprocessors

The providers behind your instance

A short list, disclosed in full in your agreement. Each one processes client data only to provide its part of the service.

Subprocessors used to run CrownEvents.OS client instances
VercelApplication hostingUS region
Supabase (on AWS)Database and file storageUS region, with a separate project for every client
ResendEmail deliveryInvitations, notifications and support messages
AnthropicAI-assisted featuresCan be switched off for your instance; data sent through its API isn’t used to train models
GoogleOptional sign-in, maps and geocodingOnly when those features are used
StripeBillingOnly once card billing is enabled, and it handles billing data only

What we never do with your data

  • Sell, rent or trade your data, to anyone, for any purpose
  • Share it with other clients, or pool it for cross-client analytics
  • Use it to train AI models, ours or anyone else’s
  • Use it for anything other than running your instance
  • Keep it past the deletion date: no archives, no escrow

Security Reviews

Completing a vendor security review?

We’re glad to walk your IT or security team through any of this in detail. Uptime targets, backup and recovery objectives, and the full subprocessor terms are written into your agreement’s hosting, security and data protection schedule.