Skip to main content
CrowAgent
Bid and tender software CrowMark for Suppliers Respond to tenders, RFPs, RFIs and questionnaires CrowMark for Buyers Read the responses you receive, against the requirements you published Compare CrowMark How it stacks up against other bid tools
Free tools and reference Tender Compliance Matrix Paste tender text, read back the requirements it states Free tools hub No account, no email gate PPN 026 explained The next edition of the Social Value Model, and the dates Procurement glossary UK bidding and tendering terms in plain English
Pricing Blog FAQ About
Sign in Request access
CrowMark for Suppliers CrowMark for Buyers Compare CrowMark
Tender Compliance Matrix Free tools hub PPN 026 explained Procurement glossary
Pricing Blog FAQ About
Sign in Request access

Security & Trust

Encrypted, documented, and auditable.

Contents

  1. Operational standards
  2. Security documentation
  3. AES-256 encryption
  4. EU data residency
  5. GDPR compliance
  6. Access controls
  7. ISO 27001 controls
  8. AI data handling
  9. Vulnerability disclosure
  10. Uptime target
  11. Deep dives
  12. Company & regulatory details
  13. Finished your review?

System status: status.crowagent.ai

Every layer, from disk to API, is named and auditable.

Operational standards

The controls every CrowAgent organisation inherits by default, from encryption to data residency to regulatory registration.

AES-256 encryption at rest

Disk-level AES-256-GCM with automatic key rotation across databases, file storage, and backups.

TLS 1.3 in transit

Forward-secret HTTPS on every request with HSTS preload and modern cipher suites only.

GDPR compliant

Subject rights supported end to end, with lawful basis, retention and deletion documented. A Data Processing Agreement is available for customers on request, currently in draft pending legal review.

EU data residency

Primary customer data is stored in the EU, in AWS eu-west-1 (Ireland). Our API runs in the EU and the web application runs in the UK. Full processing locations are listed under sub-processors below.

ISO 27001 controls

Our security controls programme is built to ISO 27001.

ICO Registered Data Controller

CrowAgent Ltd is registered with the Information Commissioner’s Office and verifiable on the ICO public register.

Security documentation

The detail behind each control, written for security and procurement teams. Jump to any topic, or contact us for an audit pack.

Security Contact

For security disclosures or audit requests, contact our security team at security@crowagent.ai

AES-256 encryption

All customer data is encrypted at rest using AES-256, and in transit using TLS 1.3. Disk encryption keys are managed and rotated by our infrastructure providers. Application credentials and API keys are rotated by us, on a documented procedure with a verification step before the old key is revoked. Database snapshots, file storage, and backups inherit the same protection.

At rest
AES-256-GCM
In transit
TLS 1.3, HSTS
Disk key rotation
Provider managed
Application key rotation
Documented procedure
Backups
Encrypted

EU data residency

  • Primary customer data is stored in Supabase’s EU region, AWS eu-west-1 (Ireland).
  • The CrowAgent API and its background worker run in the EU, in Google Cloud europe-west4 (Netherlands).
  • Supporting services may process metadata in the EU (PostHog EU Cloud, Sentry EU).
  • Web application rendering runs on Vercel in London (lhr1).
  • Other processors operate under Standard Contractual Clauses (SCCs).
  • No personal data is sent to AI providers for training. See our Privacy Policy for the full sub-processor list.
Metadata sub-processors
PostHog
EU
Sentry
SCC
Brevo
EU
Cloudflare
SCC
Calendly
SCC
Stripe
SCC

GDPR compliance

  • CrowAgent Ltd is registered as a data controller with the Information Commissioner’s Office (ICO) under the Data Protection (Charges and Information) Regulations 2018.
  • A Data Processing Agreement (DPA) is available on request for customers. It is in draft pending legal review, so terms may change before signature.
  • Data subject rights supported: right to erasure, data portability, restriction of processing, and access.
ICO contact & registration

Verifiable on the ICO public register by searching for “CrowAgent Ltd”.

Data requests: hello@crowagent.ai

Access controls

Platform access is enforced in depth: organisation-scoped roles at the application layer, Row-Level Security at the database, and multi-factor authentication at the identity layer.

RBAC

  • Org-scoped roles: Owner, Admin, Member.
  • Privileged actions audit-logged.
  • Invite-only org joins.

RLS

  • Row-Level Security enforced in Postgres.
  • Org isolation at query time.
  • Tenant data scoped to each organisation via RLS.

MFA

  • TOTP available for every account.
  • Required for Owner/Admin actions.
  • Session revocation on demand.

ISO 27001 controls

Our security controls programme is built to ISO 27001 principles, as self-declared conformity. Internal security reviews run continuously, and OWASP practices are applied to all application development. The control set, the risk register, the statement of applicability, the internal audit and the management review are maintained as documents and are available on request.

Cyber Essentials is the certification we expect to pursue first.

AI data handling

AI inference runs through server-side API calls only. Customer-facing drafting uses Google Gemini. Heavier reasoning and analysis use Anthropic’s Claude. Both are data sub-processors under signed DPAs. The boundaries below describe exactly what crosses to a model provider.

What is sent
  • Prompt context for the active task.
  • Public reference text where required.
  • Server-side API calls only.
What is NOT sent
  • Customer data for training.
  • Bulk exports or full org datasets.
  • Authentication tokens or PII.
Inference & retention
  • CrowAgent-brokered infrastructure.
  • Provider zero-retention terms.
  • Inputs not retained by the model.
Model Usage & Data Isolation
Inference traffic is brokered through CrowAgent-controlled service identities. Prompts include the minimum context required to satisfy the active task. Model responses are post-processed before storage to strip provider metadata.

Vulnerability disclosure

Report security vulnerabilities responsibly to security@crowagent.ai with the subject “Security Disclosure”. We acknowledge receipt within two business days and triage as below. These are targets we set ourselves, not a contractual service level.

On a narrow screen, this table scrolls sideways.

Severity Examples Triage target Patch target
Critical RCE, auth bypass 1 business day 5 days
High Privilege escalation 2 business days 14 days
Medium CSRF, XSS 3 business days 30 days
Low Hardening findings 5 business days Best-effort

Uptime target

99.5%

CrowAgent targets 99.5% monthly uptime, with independent public status monitoring you can check yourself.

View status page

Deep dives

Sub-processors list

Sub-processors handle metadata only. None receive customer-controlled personal data for training.

  • PostHog (EU Cloud), product analytics, event metadata.
  • Brevo (EU), transactional email delivery.
  • Cloudflare (global, SCC), CDN, DDoS protection.
  • Calendly (SCC), meeting scheduling links.
  • Stripe (SCC), billing and payment processing.
Severity levels in detail

Our severity model follows CVSS 3.1 base scoring, adjusted for environmental impact across multi-tenant data isolation.

  • Critical: active exploitation paths affecting confidentiality or integrity of customer data.
  • High: escalation paths within an authenticated session.
  • Medium: targeted attacks requiring user interaction or constrained scope.
  • Low: defensive hardening, configuration drift, or informational findings.

Company & regulatory details

ICO registration
Registered Data Controller
Company
CrowAgent Ltd
Registered
England and Wales
Data controller
CrowAgent Ltd
General Enquiries
hello@crowagent.ai
Security
security@crowagent.ai
Data request contact
For erasure, portability, restriction, or access requests, email hello@crowagent.ai. We respond within statutory timeframes.

Finished your review?

Everything above is what we can evidence today, including the gaps. If it clears your bar, the next step is access to a live workspace. If it does not, tell us which control is missing and we will say plainly whether it is on the roadmap.

Request access Book a 30-minute demo

ICO-registered data controller. EU data residency. AES-256 at rest, TLS 1.3 in transit. Built to ISO 27001 controls.

Privacy Policy Sub-processors Status Page

  • AES-256 at rest
  • TLS 1.3 in transit
  • GDPR compliant
  • EU data residency
  • Built to ISO 27001 controls
  • ICO registered
CrowAgent

CrowAgent serves both sides of a procurement, public sector and private. Suppliers answer tenders, RFPs, PQQs and SQs from bids already written. Buyers publish requirements and find the evidence.

All systems operational . Open the live status page (opens in a new tab)

Product

CrowMark for Suppliers CrowMark for Buyers Pricing Integrations Sectors Tender Compliance Matrix Free

Resources

Resources hub Blog Compare CrowMark FAQ Procurement Glossary Sources Changelog

Company

About Roadmap Contact Partners

Legal

Security Privacy Terms Cookies Accessibility

© 2026 CrowAgent Ltd. Registered in England & Wales, company no. 17076461. All rights reserved.

Status Cookie preferences

Search CrowAgent

Esc

No matches. Try a product name, a sector, or "PPN".