BaseCrew

Security

Tenant isolation by design, not by hope

BaseCrew is built for corporate companies that handle sensitive internal and client work. Your organisation's data is never visible to another customer.

How we enforce isolation

Security is architectural - enforced at the database, API, storage, and test layers.

Database isolation

Every tenant record includes organizationId. Queries always filter by it - no exceptions.

Session-bound auth

Your session token includes your organization. The server rejects cross-tenant requests.

API enforcement

All routes resolve tenant from session, not from client-supplied IDs alone.

S3 path isolation

Screenshots and files stored under organization-specific paths in object storage.

Automated tests

Isolation test suite with duplicate names across two orgs - run on every deploy.

No UI-only security

We do not rely on hiding menu items in the browser as our security boundary.

Retention & deletion

Clear rules for how long organisation data stays available after you stop paying.

01

Active subscription

Data retained while your subscription is active. Screenshots tiered to lower-cost storage over time per plan.

02

Deactivated account

2-month (60-day) grace period with email warnings at 30 and 7 days before permanent deletion. Reactivate any time within this window to keep your data.

03

After deletion

Operational data and files permanently removed from our systems.

Ready to run your team on isolated infrastructure?

Start free