Your catalogue, open to AI shoppers.

See how
Skip to main content

Your Data. Protected.

Encryption at rest and in transit protects conversations and sensitive data.

Why Security Matters for Learning AI

Secure data enables smarter agents

Maya's Conversations

Perfect memory requires perfect security. Every preference, constraint, and decision encrypted.

Felix's Learning Accuracy

Compound learning needs clean, trusted data. Security prevents poisoned learning.

Your Ad Spend Data

Millions in Meta, Google, TikTok campaigns. Competitor isolation is critical.

Compound Learning

Intelligence improves over months. Long-term data security = long-term accuracy gains.

Security at Every Level

Protection built into everything we do

Encryption at Rest and in Transit

Strong encryption at rest and in transit. Data encrypted everywhere it moves. Agents learn from protected data.

You Approve Changes

Agents propose changes and you approve them before they run. Revoke access anytime.

Complete Isolation

Your learning data separated from competitors. Stays in your account.

Threat Detection

Infrastructure monitoring across the stack.

Access Controls

Account-level access controls. Multi-factor authentication on roadmap.

Audit Logs

Activity logs for account-level changes. Available in Settings.

Meeting Global Standards

Compliant with major privacy regulations. Hosted on SOC 2-compliant infrastructure (Vercel, AWS/GCP).

GDPR

Active

European privacy law compliance. Your data rights protected globally.

Status: Compliant

CCPA

Active

California privacy law compliance. You control and delete your data anytime.

Status: Compliant

Your Privacy Matters

You control your data at all times

Complete Transparency

Clear info on what data we collect and why.

Your Data, Your Rules

Export anytime. Delete with one click.

Minimal Collection

AI agents only access data needed for insights.

Account-Bound

Your data stays in your tenant. Not shared with other customers, not sold to third parties. See our Privacy Policy for full data-handling terms.

Full Control

Choose what data to share. Opt in or out of analytics.

Clear Deletion

Delete your data whenever you want.

Common Questions

Quick answers about security and privacy

Where is my data stored?

Encrypted at rest and in transit. Your learning data stays in our protected infrastructure.

Do you store passwords?

No. You sign in with a one-time link or a passkey, and platform connections use OAuth wherever the platform offers it. Revoke access anytime without affecting your accounts.

What if there's a breach?

If we confirm a breach affecting your data, we will tell you within 72 hours, with what happened and what we are doing about it.

Can I export my data?

Yes. Export anytime in standard formats. Keep all conversations and insights even after canceling.

Is data shared with other customers?

Account-bound. Your learning data stays in your tenant. See our Data Processing Addendum for tenant-isolation details.

What happens if I cancel?

Data kept 30 days for recovery, then permanently deleted. Request immediate deletion anytime.

Do you support SSO?

On roadmap for Enterprise plans. SSO/SAML integration coming with Okta, Azure AD, and Google Workspace support.

How often do you test security?

Internal security reviews ongoing.

Assistant connectors

What happens when a user connects a third party AI assistant to Cresva. The same wording appears in our privacy policy and terms. Last reviewed 2026-09-10.

What a connected assistant can read

Cresva operates a Model Context Protocol server at https://cresva.ai/mcp. A user may connect a third party AI assistant, such as Claude, ChatGPT or Cursor, to that server. The assistant is the client: it authenticates to Cresva using OAuth 2.1 and holds its own access token.

A connection can read only the brands the user selected on the Cresva consent screen at the time of granting, and only through the tools that the granted scopes permit. It cannot enumerate or reach an account the user did not grant, and it cannot reach another customer's data.

The connector is read only by default. Of the tools the server registers, all but one are reads. The single tool that is not a read opens a price negotiation on the customer's own storefront, and it requires a scope that is off unless the user turns it on when granting.

The assistant acts as the user, and every call is logged

A connection is granted by an individual user and carries that user's identity. Anything the assistant reads is what that user is entitled to read, and their permissions are re-evaluated at the time of each call rather than frozen when the grant was made. A user who loses access to a brand loses it through the connector at the same moment.

Every tool call is written to Cresva's audit log against the granting user, the assistant that made it and the grant it was made under. An administrator can therefore attribute any connector activity to a named person. Audit records are retained on the same schedule as other account audit data.

What leaves Cresva's systems

When a connected assistant calls a tool, Cresva returns the answer to that tool call to the assistant, over TLS. Nothing else is transmitted: Cresva does not send the assistant vendor credentials, connected platform tokens, other customers' data, or any bulk export of the customer's account.

Once an answer reaches the assistant it is governed by the agreement between the user and that assistant's vendor. Cresva has no visibility into, and makes no representation about, how a vendor stores, processes or trains on content the user brings into their own conversation. A customer evaluating that risk should read the vendor's terms.

Grants, tokens and retention

Cresva stores, for each connection: the registered client, the granting user, the brands and scopes granted, the time of grant, and the time the connection was last used. Access tokens and refresh tokens are stored as hashes rather than in a recoverable form.

Access tokens are short lived. Refresh tokens are single use: a refresh issues a new refresh token and invalidates the one presented, and presenting a token that has already been used revokes the grant. Records of a revoked grant are retained as audit history rather than deleted, so that past access remains attributable.

How to revoke a connection

A user can revoke a connection at any time from Connected apps in their Cresva settings. Revocation takes effect immediately: the tokens are invalidated and the next call from that assistant is refused. Revoking one user's connection does not affect any other user's.

Removing a user from the Cresva account, or removing their access to a brand, has the same effect on what their connections can reach, because permissions are evaluated per call.

Test credentials read simulated data

Cresva issues test API keys, distinguishable by their sk_test_ prefix, alongside live keys. A request authenticated with a test key reads simulated data only. It does not read the customer's connected accounts and cannot change any record. Test keys exist so that an integration can be built and run in a customer's own CI without touching production data.

Questions About Security?

Talk to us about compliance, data handling, or custom security requirements.