Encryption
All traffic to our website and applications is served over TLS. Data stored in our managed databases and object storage is encrypted at rest.
Security is part of how we build, not a checklist at the end. Here is how we protect our own systems and the software we deliver to clients.
Last updated: February 2026
All traffic to our website and applications is served over TLS. Data stored in our managed databases and object storage is encrypted at rest.
Access to production data follows least privilege.
Every change is reviewed before it reaches production.
We run on hardened, managed cloud infrastructure with isolated environments for development, staging and production. Infrastructure changes are versioned and reversible.
Application and infrastructure logs are collected centrally with alerting on anomalies. We maintain an incident response process covering triage, containment, client notification and post-incident review.
Production databases are backed up on an automated schedule with point-in-time recovery. Restores are tested so that recovery targets are realistic rather than theoretical.
If you believe you have found a vulnerability, email us with details and steps to reproduce. We will acknowledge within two business days and keep you updated. Please do not access or modify other people's data while testing.
For contracted engagements we can support security questionnaires, data processing agreements, penetration test coordination and compliance-driven architecture requirements.
Contact us at hello@crestengage.com or +1 (805) 288-0743.