# Secure by design. Built for trust.

Crevio runs a real business on your behalf — taking payments, sending messages, acting in your name. Here is how we keep that power safe.

[Contact our security team](mailto:support@crevio.co)[View subprocessors](/legal/subprocessors)

Protection statusLive

- Encryption in transit & at restActive
- Training on your dataNever
- Tenant isolationEnforced
- PaymentsPCI Level 1

How we protect you

## Power, with guardrails on every side.

### You hold the controls

Decide how much your agent can do on its own. Require human approval for sensitive moves — publishing, spending, sending — and review every draft before it goes live.

Agent autonomyLive

- Spend ad budgetAsk first
- Draft a product pageAuto

### Never trained on your data

Your business data, prompts, and agent memory are never used to train foundational models. What you build on Crevio stays yours.

### Encrypted secrets & connections

API keys and OAuth tokens for the apps you connect are encrypted at rest and scoped to the workflows that need them — never shown in plaintext.

StripeMetaGoogleSlack

### Isolated by tenant

Every workspace, its agent context, and its customers are logically separated. Strict boundaries keep your data inaccessible to any other account.

### Sandboxed execution

When your agent runs code to build and operate your business, it does so inside isolated sandboxes — walled off from other tenants and our core systems.

### Role-based access

Choose who on your team can view, edit, or approve work. Member roles enforce least-privilege access across the whole workspace.

### Compliant infrastructure

Hosted with established cloud providers that meet industry security and privacy standards, with encryption in transit and at rest.

[View our subprocessors](/legal/subprocessors)

## Frequently asked questions

Need something more specific? We're here to [help you out](mailto:support@crevio.co).

### Is my data used to train AI models?

No. Your business data, prompts, and agent memory are never used to train foundational models. Your work stays your work.

### How are my connected accounts and API keys secured?

API credentials and OAuth tokens are encrypted at rest and scoped to specific workflows. They are never exposed in plaintext in logs or interfaces, and access is limited to authorized actions.

### Can my agent take actions without my permission?

You’re in full control. Run your agent fully autonomously, or require human approval for specific actions like publishing a page, sending a campaign, or spending budget. Nothing irreversible happens without your sign-off.

### Is Crevio multi-tenant, and how is customer data isolated?

Crevio is a multi-tenant platform with strict logical isolation between workspaces. Your business data, agent memory, and workflows are not accessible across accounts.

### How are payments handled?

Payments are processed by Stripe, a certified PCI Service Provider Level 1 — the most stringent level of payment security. Raw card details go straight to Stripe and are never stored on our servers.

### Who are your subprocessors?

Crevio relies on established cloud and infrastructure providers that maintain industry security and privacy standards. The full list is published on our [subprocessors page](/legal/subprocessors).

Canonical URL: https://crevio.co/security
