Last updated: Oct 20, 2025
At Cruxtro, we believe trust is the foundation of intelligent collaboration.
Our platform is built with privacy, data integrity, and enterprise-grade security at its core — so your product data stays safe, encrypted, and fully under your control.
This document outlines how we secure your data across every layer of the Cruxtro stack.
Cruxtro runs on a modern, cloud-native architecture hosted entirely on Google Cloud Platform (GCP) — using secure, isolated environments for every component of our system.
| Component | Platform | Security Highlights |
|---|---|---|
| Backend | Google Cloud Run | Containerized microservices deployed in a fully managed, auto-scaling environment. Each service is authenticated using IAM and service accounts. |
| Database | Cloud SQL for PostgreSQL | Data encrypted at rest and in transit (AES-256 & TLS 1.3). Access restricted via private VPC and IAM roles. |
| Frontend | Vercel | Served securely over HTTPS with automatic SSL/TLS certificates. CI/CD pipelines ensure verified and integrity-checked builds. |
| Authentication | Clerk | Manages user authentication, registration, and sessions using industry-standard encryption and compliance. Provides built-in support for SSO, 2FA, and session management. |
All credentials, API keys, and environment variables are managed using Google Secret Manager, ensuring:
Only specific backend services can access secrets, and only for the duration of authorized operations.
Cruxtro uses Google Cloud AI to power product intelligence, summarization, and insight generation.
AI interactions are processed through ephemeral and encrypted sessions, ensuring:
Cruxtro never sends your data to external AI systems for training.
Cruxtro uses Razorpay for secure payment processing. Razorpay is PCI DSS Level 1 compliant — the highest level of payment security certification.
Authentication and user management in Cruxtro are powered by Clerk — a secure, compliant identity platform designed for modern web apps.
Clerk provides:
Cruxtro complements Clerk with:
All cookies and tokens are HttpOnly, Secure, and SameSite protected.
Cruxtro continuously monitors for performance and security anomalies using Google Cloud Monitoring & Logging.
Cruxtro’s infrastructure and policies are aligned with global compliance standards:
We provide self-service data export and deletion options in compliance with user data rights and regulatory obligations.
We welcome security researchers and ethical hackers to help us identify vulnerabilities.
If you believe you’ve found a security issue, please contact us responsibly at security@cruxtro.com.
We respond promptly to all verified reports and will acknowledge your contribution.
Your data powers your product decisions — and protecting it powers ours.
Cruxtro is built to enable AI-native product teams to work intelligently without sacrificing security, privacy, or compliance.
We build with trust by design — intelligence by intent.
For security or compliance questions:
Email: support@cruxtro.com
Website: www.cruxtro.com