Explicit scope
Queries, background jobs, exports, and file paths carry explicit tenant scope. Jobs re-load and re-verify their tenant rather than trusting what was queued.
Security
Customer data in Crescove belongs to a Brand inside an Organization, and that scope is enforced on the server for every read and write. Client-supplied Organization or Brand identifiers are treated as hints, never as authorization.
Queries, background jobs, exports, and file paths carry explicit tenant scope. Jobs re-load and re-verify their tenant rather than trusting what was queued.
What a staff member can do is a capability check. Access details and internal notes are gated separately from ordinary customer data.
Operating the Crescove platform for Weteamsteve LLC is a different privilege from owning an Organization. Being an Organization owner does not grant that access.
Public Brand sites, the staff workspace, and these product sites are separated by hostname. An unknown host fails safely instead of falling back to someone else's Brand.
Sessions are cookie-based with CSRF protection on the web, and bearer tokens held in the Keychain on iOS. Files are stored privately and retrieved through signed URLs.
Crescove is not certified under SOC 2, HIPAA, PCI, GDPR, or CCPA, and we do not present an uptime guarantee. We describe what is implemented and verified in staging.
Tell us how your business runs today and we will walk through what is available now, what is still being built, and what would need to be connected for you.