C
Crestline / ai
Trust

Security Policy

Effective as of 2025-07-29

At Crestline Intelligence Private Limited (“Crestline”, “we”, “our”, or “us”) we treat the security, reliability, and integrity of our infrastructure as a non-negotiable commitment. Our security policy encompasses a wide array of proactive protections and operational governance mechanisms developed in alignment with global standards.

1Organizational Commitment

Security monitoring is continuous. All information is strictly analyzed, and access is conducted through encrypted protocols aligned with ISO 27001, SOC 2, and NIST frameworks. Crestline operates a dedicated internal Security Operations Center (SOC) and regularly undergoes SOC 2 and ISO audits.

2Data Protection and Encryption

All systems handling customer information adhere to standardized cryptographic procedures ensuring enterprise-grade protection. Systems supporting data transmission use TLS 1.3 encryption, while all stored data utilizes AES-256 military-grade encryption protocols.

3Access Control and Authentication

We implement strict role-based access management (RBAC) and enforce multi-factor authentication (MFA) for all internal users. Account provisioning and deprovisioning follow least-privilege principles. All internal and external access attempts are logged, analyzed in real time, and reviewed for compliance.

4Vulnerability Management and Incident Response

We undergo regular internal and third-party penetration testing, red-team simulations, and code audits. A defined incident response workflow includes identification, containment, eradication, recovery, and post-incident review aligned with NIST SP 800-61 and CIS guidelines.

5Infrastructure Security Architecture

Our infrastructure benefits from multilayered security architecture, including distributed denial-of-service (DDoS) protection, intrusion detection systems (IDS), firewalls, and web application firewalls (WAF). Endpoint Detection and Response (EDR) tools monitor all workstations and servers.

6Internal Employee Governance

All employees undergo comprehensive background checks and receive mandatory security training annually. Privileged access is granted only for specific tasks, time-bound, and revoked immediately post-completion. Violations of internal policy result in disciplinary action including termination and legal prosecution.

7Legal & Compliance Disclosures

We comply with all applicable data privacy, electronic security, and cybersecurity laws across operational jurisdictions. Crestline actively collaborates with regulatory bodies to ensure ongoing transparency and accountability in its operations.

Questions about our security posture? Contact info@crestlineintelligence.com.