Security and compliance
How Crew Pass handles your data
Security companies hand us licence numbers, personal details and rosters for real operations. Here is exactly what is in place, in plain terms.
Records
Reports that prove themselves
Training registers, acknowledgement reports and readiness reports carry a verification code, a timestamp, a row count and a content hash. Anyone you hand a report to can confirm it hasn't been altered, without needing a login.
- Verification code and content hash on every export
- Checked by the person holding the report, no login needed
- Completion records are fixed at the database level, not just in the app
Re-run the check on this code and the hash has to match, character for character, or the report has been changed since it left Crew Pass.
Access
Who signs in, and what they see
Company data is kept separate by tenant. Admins sign in with an email and password. Guards never hold a password at all: they get a single-use link, and what they see is their own pass, their own shifts and their own inductions.
- One company's data is never mixed with another's
- No worker passwords to leak, reset or share around a site
- Modules you switch off disappear from navigation, the portal and the API
The record
Checks and overrides stay on the record
Licence checks record their result and re-run every 7 days. Where a rostering block is overridden, or a timesheet line is denied, the reason is kept with it. Once a worker finishes an induction, the completion can't be edited afterwards.
Also in place
The rest of the short list
Encryption in transit
All traffic between your browser or phone and Crew Pass runs over HTTPS.
Immutable completion records
Once a worker completes an induction, the completion time, start time, status and answers can't be changed. That is enforced at the database level, not just in the app.
Licence data handling
Licence checks run against the relevant state register, and the result, including type, expiry, activities and conditions, is stored against that worker. Name mismatches are queued for a human to confirm rather than resolved automatically.
Company data on request
You can ask for your company's data, or for it to be removed. Email [email protected] and we'll action it.
Questions before you start?
Email us directly, we read every message ourselves.