Trust & Security Center
You’re about to hand a partner the keys to your business. It’s fair to ask how they are secured. This is our own posture, in one place — the attestations, the controls, the agreements we’ll sign, and the reason we keep some things deliberately quiet.
The short, honest version
CRC Cloud is not SOC 2 attested and not ISO 27001 certified. The datacenter that houses our hardware is — those are the facility operator’s credentials, and we will not borrow them. Our own practice is organized around the NIST Cybersecurity Framework 2.0, and everything below describes what we actually do rather than what someone else has certified.
We are telling you this in the first paragraph instead of the fine print because you are about to hand a partner the keys to your business, and you should not have to dig for the one fact a competitor would most like you to miss. If a certification is a hard requirement for your firm, say so on the assessment call and we will tell you plainly whether we are the right fit — sometimes the honest answer is that we are not.
How we secure our own house
We hold ourselves to the standard we sell. The pillars:
The facility, on the record
Your data can live in a carrier-neutral Southern California datacenter engineered to a concurrently maintainable, Tier III-standard design, maintaining SOC 1 & SOC 2 Type II, ISO 27001 and PCI DSS attestations, and NIST 800-53 (PE) High alignment — with N+1 redundant power and cooling and geo-separate replication.
24/7 monitoring
A security operations center watches the environments we manage around the clock, with managed detection and response and centralized SIEM logging behind it.
Hardened access
MFA on administrative access, least-privilege by default, encryption in transit and at rest, and a NIST Cybersecurity Framework 2.0-based practice governing how we operate.
Tested resilience
Encrypted, immutable backups with geo-separate replication and test-restores — the recovery discipline we require of clients, applied to ourselves.
Attestations & alignment
What underpins the infrastructure your workloads run on:
| Standard | Who holds it & what it covers |
|---|---|
| SOC 1 & SOC 2 Type II | Independent audits of the facility’s security, availability, and controls over time |
| ISO 27001 | An internationally recognized information-security management standard |
| PCI DSS | Payment-card data-security requirements at the facility level |
| NIST 800-53 (PE) High | Physical and environmental controls aligned to a federal high-impact baseline |
| Tier III-standard design | Concurrently maintainable infrastructure with a 99.9% uptime service level |
| NIST CSF 2.0 | The framework our own security practice is organized around |
The facility operator’s attestation reports can be requested under NDA during evaluation, subject to the operator’s own distribution terms. See the datacenter → See how we align clients to compliance →
The agreements we’ll sign
Trust should be contractual, not verbal. As part of onboarding we routinely execute:
| Document | When |
|---|---|
| Business Associate Agreement (BAA) | When we manage systems that handle your protected health information |
| Mutual NDA | On request, before or during evaluation |
| Security addendum / questionnaire | When your procurement or insurer requires it — we’ll complete it |
| Service agreement | One-year initial term, then month-to-month with 60 days’ notice, no exit fees |
Why we keep some things quiet — on purpose
We don’t publish our client list, the exact location of the datacenter, or the specific security tools we run. That isn’t evasiveness — it’s a control. A public map of who we protect, where their data sits, and which products guard it is precisely the reconnaissance an attacker wants. We share all of it with you, in detail, under NDA. The quiet is part of the protection.
Four decades of verifiable history back it up — our 1980s–90s catalogs and press coverage are on the record. See the receipts →
What happens when your engineer isn’t available
It is a fair question to ask a small team, and it deserves a specific answer rather than reassurance.
Every engineer here is senior
We don’t staff a junior tier. There is no first line whose job is to take a message and escalate — the person who picks up your ticket is qualified to resolve it. That is the main reason a compact team can carry the load a larger one needs headcount for.
You get a named account manager
One senior person is assigned to your business as your point of contact for every ticket. They own it end to end: coordinating the help desk, doing the work, and reporting back to you. You are not explaining your environment to a stranger each time.
And a named backup behind them
Every account has a designated second who knows the environment and steps in when your account manager is unavailable — illness, leave, or simply another incident. Cover is assigned in advance, not improvised on the day.
Someone senior is always on
We run 24/7. Outside business hours there is always a senior engineer available — not an answering service taking a message for the morning. That is the same standard that backs the published response times.
Your environment is documented in our systems rather than carried in one person’s head, and that documentation is yours to take at any time — see switching. If continuity is the question that decides this for you, ask it on the assessment call and ask our references about it too.
FAQ
Will you sign a BAA, NDA, or security addendum?
Yes. We sign a Business Associate Agreement when we handle protected health information, and we routinely sign NDAs and reasonable security addenda as part of onboarding. If your procurement process has a security questionnaire, we'll complete it.
Where is your datacenter, and why won't you name the exact location or your tools?
On infrastructure we own inside a carrier-neutral Southern California facility of concurrently maintainable, Tier III-standard design. Its operator holds SOC 1 & SOC 2 Type II, ISO 27001 and PCI DSS attestations — those are the operator's credentials, not CRC Cloud's. We keep the precise location and our specific toolset confidential on purpose — publishing them would hand attackers a map. That discretion protects our clients, not us.
Do you carry insurance?
Yes. We maintain business liability and cyber/errors-and-omissions coverage appropriate to a managed security provider. Details are shared under NDA during evaluation.
Can we get references or talk to a current client?
Yes — privately, with clients who've agreed to take reference calls, as part of a serious evaluation. We publish role and industry only, never a public client roster, for the same security reason we keep our stack confidential.