Crew Keys / Security and Trust

Security and Trust

Security and trust for shared-fleet operations.

Crew Keys is designed around organization-scoped access, role separation, durable operational records, and conservative deployment claims. Security depends on both the application and the environment where it is deployed.

Application controls

Crew Keys separates organization data at the application and database-query level, uses authenticated sessions for workspace access, and distinguishes administrative access from member operational access.

Operational write paths are designed to validate organization ownership and important vehicle-state transitions on the server rather than relying only on browser controls.

Deployment responsibility

Hosting, network boundaries, identity requirements, logging, backups, encryption, vulnerability management, and compliance controls depend on the selected deployment environment and customer configuration.

Crew Keys should not be represented as FedRAMP, DoD IL5, or otherwise certified unless the specific deployed system has completed the required authorization and control process.

Data minimization

Lower-privilege fleet views are intended to expose only the operational information needed for checkout and availability decisions. Administrative and site-owner capabilities are separately authorized.

Report a concern

Security questions or suspected vulnerabilities should be sent through the Crew Keys contact page with enough detail to reproduce or assess the issue. Do not include passwords or other secrets in the message.

Questions?

Talk with Crew Keys about your deployment.

Use the contact form for product, security, implementation, or procurement questions.

Contact Crew Keys