How Crux handles your data.
Crux is the system of action for your brokerage. The agent performs the work, then hands results off to your AMS, CRM, and carrier systems of record. While a job runs it works with the data that job needs, and we protect that data with care: one isolated environment per customer, enterprise SSO, encryption in transit and at rest, an audit log on every action, and a completed SOC 2® Type II examination. Request the report, or ask us anything your security review needs.
Enterprise-grade security, built for insurance.
Every layer of Crux is designed to keep your data safe, private, and compliant.
Every organization gets its own completely separate data environment. Your data is never shared, commingled, or accessible by other customers. Period.
Enterprise SSO (Okta, Azure AD, Google Workspace), custom user roles, and granular permissions. Control exactly who can see, edit, and approve at every level of your organization.
Independently examined against the AICPA Trust Services Criteria for Security. Type II means our controls were tested over a period of time, not just at a point in time. Report available under NDA.
All data is encrypted in transit and at rest. Credentials and secrets live in dedicated vaults, never in application code or configuration files.
Administrative, physical, and technical safeguards for protected health information are in place. Formal HIPAA attestation is in progress.
Every action is logged and traceable. Full audit history for compliance reviews, incident investigations, and regulatory reporting.
Where is my data stored?
In secure, SOC 2-audited cloud infrastructure in the United States. Every organization gets a completely isolated data environment that is not shared with any other customer.
Can other customers access my data?
No. Every organization has its own dedicated, isolated environment. There is no shared database or cross-tenant data access. Your data never touches another company's environment.
Do you support single sign-on?
Yes. Crux supports enterprise SSO with Okta, Azure AD, Google Workspace, and other major identity providers, so your team uses the same credentials they use for the rest of your organization. We also support custom roles and granular permissions.
Is Crux HIPAA compliant?
Formal HIPAA attestation is in progress. Administrative, physical, and technical safeguards for protected health information are already in place across the platform, and BAAs are available on request.
Do you have a SOC 2 report?
Yes. Crux completed a SOC 2 Type II examination. Type II means an independent auditor tested that our controls operated effectively over a period of time, not just that they were designed correctly on a given day. The full report is available under NDA. Contact our team to request it.
How can I review your security posture?
Contact our team to request the SOC 2 Type II report, security policies, and a summary of controls. We are happy to walk your security or compliance reviewers through it.
How do you handle vulnerability management?
We maintain a continuous vulnerability management program including regular security assessments, dependency scanning, and responsible disclosure processes. Critical vulnerabilities are addressed immediately.
Need more detail on our security posture?
Request our SOC 2 Type II report and supporting security documentation, or book time with our team to walk through it.
