Security
Security and compliance, end to end
Your data, your subscribers' data, and your sending infrastructure are protected by the standards that regulated industries rely on.
Compliance
Audited against the regulations that matter to your business
Crownvo is built to meet the privacy and anti-spam regulations across the markets you sell into. Compliance reports and signed DPAs are available on request.
GDPR
EU General Data Protection Regulation compliant. DPA available for all customers. Standard Contractual Clauses for cross-border transfers.
CAN-SPAM
Compliant with the US CAN-SPAM Act. Built-in unsubscribe links, physical address, and suppression handling on every send.
CCPA
California Consumer Privacy Act compliant. Data export, deletion, and opt-out workflows built into every account.
SOC 2 Type II
Annual SOC 2 Type II audit covering security, availability, and confidentiality. Report available under NDA.
ISO 27001
Information security management certified. Certificate available on request.
Data handling
Where your data lives, who can access it, and what happens when you leave
We treat your subscriber data as if it were our own. Residency options, granular retention controls, and a documented deletion process.
Data residency
Customer data stored in your choice of US, EU, or APAC regions. Encrypted backups stay in the same region.
Per-tenant data isolation
Each tenant's data lives in its own logically isolated namespace. No cross-tenant queries, ever.
One-click data export
Export your full subscriber, campaign, and automation data as CSV or JSON — any time, no support ticket needed.
Deletion on request
Account deletion cascades to all backups within 30 days. Audit log of every deletion event is available on request.
Data Processing Agreement
DPA available for all customers, signed via click-through. EU SCCs appended for cross-border transfers.
Subprocessor transparency
Public subprocessor list with 30-day change notification. Right of objection on Enterprise plans.
Infrastructure
Encrypted everywhere, isolated by tenant, monitored 24/7
Crownvo runs on enterprise-grade cloud infrastructure with the encryption, redundancy, and uptime guarantees that production workloads require.
Encryption at rest
AES-256 encryption for all stored data, including backups and snapshots. Per-tenant key options on Enterprise plans.
Encryption in transit
TLS 1.3 enforced on all customer-facing endpoints. HSTS with includeSubDomains. Modern cipher suites only.
99.99% uptime SLA
Active-active multi-zone deployment with automatic failover. Service credits issued when the SLA is missed.
Multi-region redundancy
Customer-facing traffic routed through redundant points of presence. Database replicas in three or more zones.
DDoS + WAF
Network-layer DDoS protection plus a managed web application firewall with OWASP Top 10 coverage.
24/7 monitoring
Around-the-clock infrastructure monitoring with on-call escalation. Mean time to detect under 60 seconds.
Access
Granular permissions, hardware-backed authentication, full audit trail
Control who can do what — across your team, your customer accounts, and your service integrations.
Two-factor authentication
TOTP and email-based 2FA. Required for all admin accounts on paid plans. Enforced org-wide via policy.
SAML SSO + SCIM
Single sign-on and automated user provisioning via SAML 2.0 and SCIM 2.0. Available on Enterprise plans.
Role-based access control
Granular roles for admin, marketer, analyst, and viewer. Custom roles on Enterprise plans.
IP allowlists
Restrict dashboard access to a list of approved IP ranges. Per-team overrides on Enterprise plans.
Session management
Configurable session timeouts. Admins can revoke active sessions for any user in one click.
Audit log
Every admin action — logins, permission changes, exports — logged with timestamp, user, IP, and user agent.
What this means for you
Less procurement friction, faster enterprise deals, and peace of mind for the team that has to fill out the security questionnaire.
For your security team
Annual SOC 2 Type II report, penetration test summary, and a current vulnerability disclosure policy — all available under NDA on request.
For your legal team
Click-through DPA with EU SCCs, a public subprocessor list with 30-day change notification, and GDPR-aligned processing by default.
For your enterprise buyers
Trust badges and security posture on every page. Pre-completed questionnaires for the common frameworks. 24-hour response on security inquiries.
For your IT team
SAML SSO and SCIM provisioning to plug into Okta, Azure AD, or Google Workspace. Granular RBAC and IP allowlists on Enterprise plans.
Security questions, answered
The questions we get most from security and compliance teams. For anything else, email security@crownvo.com.
Questions about compliance?
Talk to our team about your specific compliance needs — or grab our SOC 2 summary under NDA.
No credit card required · 14-day free trial on any paid plan