# Crystal Knows — Security & Compliance Context

> Source: https://security.crystalknows.com/ · Generated 2026-07-27

This document contains Crystal Knows' complete security, compliance, and policy documentation. It is intended to support security questionnaires, vendor due diligence reviews, and compliance assessments. All content is current as of the date above.

---

Last Updated: 02/24/2026

# Security, Data Protection & Responsible AI Overview

This page summarizes Crystal Project Inc.’s (“Crystal”) approach to data protection, system security, and responsible use of AI-driven insights.

Crystal provides personality-based communication insights through a purpose-built probabilistic modeling system. Security, privacy, and human oversight are foundational to the platform’s design.

---

## 1. Data Protection Roles

Crystal acts as a **data processor**. Our customers act as **data controllers**.

Customers determine:

- How and why the platform is used
- What data is entered
- Who has access
- How outputs are applied within their organization

Crystal processes personal data only in accordance with customer instructions and contractual agreements.

Using Crystal does not create a new category of controller responsibility beyond standard SaaS usage.

---

## 2. AI System Overview

### System Purpose

Crystal provides communication and personality-based insights to support professional interactions.

The platform is purpose-built and is not a general-purpose AI system.

### Modeling Approach

Crystal is built on a proprietary Bayesian statistical modeling framework.

The system uses probabilistic inference to estimate likely communication and personality preferences based on observed signals and publicly available professional information.

Outputs are likelihood-based insights and are advisory in nature.

### Human Oversight

All system use is initiated by human users.

Crystal does not perform automated decision-making, execute actions, or make determinations without human involvement.

Users are responsible for how insights are applied in their business context.

---

## 3. Responsible AI Principles

Crystal’s system is designed around the following principles:

- Transparency about system functionality
- Human oversight and user control
- Purpose limitation
- Avoidance of automated decision-making impacting individuals’ legal rights
- Aggregate-level performance monitoring

Customer data is not used to train or fine-tune external large language models.

---

## 4. Data Sourcing and Processing

Crystal may process:

- Name
- Work email address
- Job title and professional background
- Publicly available professional information
- User-provided inputs

Crystal does not intentionally collect or process special category data such as health data, biometric data, political opinions, religious beliefs, or government identification numbers.

Customers are responsible for ensuring their downstream use of insights complies with applicable laws.

---

## 5. Transparency and Customer Responsibilities

Customers are responsible for meeting their own privacy and transparency obligations under applicable laws.

When assessments are used, respondents voluntarily provide information.

For prediction use cases, insights are generated using limited identifiers and publicly available professional information.

Customers determine how transparency requirements apply in their jurisdiction.

---

## 6. Security and Infrastructure

### Security Program

Crystal maintains a SOC 2 Type II certification covering security controls.

The security program includes:

- Role-based access control, least privilege, and MFA for all workforce identities
- Encryption in transit and at rest
- High-availability cloud architecture with multi-AZ deployment
- Centralized security logging, monitoring, and alerting
- Incident response procedures
- Independent third-party penetration testing performed annually
- Vendor risk management

### Hosting Environment

Crystal is hosted on Amazon Web Services (AWS) in the United States.

Production systems are deployed in a multi-availability-zone architecture within the primary AWS region. Crystal relies on AWS physical and infrastructure controls while implementing application-level, identity, and organizational security controls on top of the cloud infrastructure.

### Access Controls

Access to customer data is restricted using role-based access controls.

Authorized personnel may access data only for operational, support, or security purposes.

---

## 7. Data Rights and Retention

### Data Subject Requests

Crystal supports search and export of relevant personal data in structured formats (e.g., CSV, JSON) to assist customers in responding to data subject access requests.

### Retention

Data retention is governed by contractual terms and internal data management policies.

Customer data may be deleted upon request, subject to legal or regulatory requirements.

---

## 8. Governance and Oversight

Crystal maintains formal governance processes including:

- Risk management and periodic risk reviews
- Secure development and change management controls
- Vulnerability scanning and independent annual penetration testing
- Incident response planning and tabletop exercises
- Disaster recovery planning and resilience testing
- Third-party risk management

No significant security incidents occurred during the most recent SOC 2 Type II audited period.

---

## Additional Documentation

For further documentation, including:

- SOC 2 Type II report
- Data Processing Agreement
- Privacy Policy
- Terms of Service

Please visit our Trust Center or contact:  
security@crystalknows.com

---

# Policies

## Security

### Access Control Policy

# Access Control Policy

**Policy Owner:** Paul Jones  
**Version:** 2.1  
**Effective Date:** 2023-01-18  
**Last Reviewed:** 2026-02-24  

---

## 1. Purpose

To ensure that access to systems, infrastructure, and data is restricted to authorized individuals based on role and business need.

---

## 2. Scope

This policy applies to:

- All systems that process, store, or transmit Confidential or Customer data
- Production infrastructure
- Source code repositories
- All employees and authorized contractors

---

## 3. Access Control Principles

Crystal Project applies the following principles:

- Least privilege
- Role-based access control (RBAC)
- Unique user identities
- Multi-factor authentication (MFA) required for all workforce identities
- Prompt removal of access upon termination or role change

Access not explicitly granted is denied by default.

---

## 4. Identity and Authentication

- All personnel must use unique user accounts.
- Shared user accounts are prohibited except for technical service accounts.
- Google Workspace is used as the primary identity provider where applicable.
- MFA is required for all workforce identities and for all privileged access. Exceptions require documented approval from the Policy Owner.
- Passwords must comply with organizational standards and be protected using appropriate cryptographic controls.

---

## 5. Provisioning of Access

Access is granted based on role and business need.

Provisioning is performed by authorized administrators using role-based groups where possible.

Access requests may be communicated through internal communication channels (e.g., Slack, email) and must be approved by management or the Policy Owner prior to granting privileged or production-level access.

System audit logs and platform-level access records provide evidence of access grants and modifications.

---

## 6. Modification of Access

When an employee changes roles:

- Access rights must be reviewed.
- Access not required for the new role must be removed.

Management is responsible for initiating access adjustments when role changes occur.

---

## 7. Deprovisioning of Access

Access must be removed promptly upon:

- Termination of employment
- End of contract
- Role change where access is no longer required

Maximum time for production access removal is 24 business hours.

Deprovisioning may occur immediately for high-risk or privileged roles.

User IDs must not be re-used.

---

## 8. Privileged Access Management

Administrative or privileged access:

- Is restricted to personnel with defined operational need
- Requires MFA
- Is limited in scope
- Is subject to logging and monitoring through system-level audit capabilities

---

## 9. Access Reviews

Access rights are reviewed periodically to ensure they remain appropriate based on role and business need.

Access reviews are conducted by management and include:

- User accounts
- Administrative accounts
- Service accounts where applicable

Review results are documented and retained.

---

## 10. Source Code Access

Access to source code repositories:

- Is restricted based on role
- Is controlled through centralized version control systems
- Does not allow anonymous or public modification of private repositories

Protected production branches restrict direct modification.

---

## 11. Network and Remote Access

Remote access to production systems must:

- Be encrypted
- Require authentication
- Be restricted to authorized users

Guest or public network access must be logically separated from production systems.

---

## 12. Exceptions

Exceptions must:

- Be documented
- Include justification
- Be approved by the Policy Owner

---

## 13. Violations and Enforcement

Violations may result in:

- Removal of system access
- Corrective action
- Disciplinary measures
- Termination of engagement where appropriate

---

## 14. Review and Revision History

| Version | Date | Description | Author |
|----------|------------|-------------|----------|
| 1.1 | 2023-01-18 | Prior revision | Paul Jones |
| 2.1 | 2026-02-24 | Aligned to operational practice | Paul Jones |

### Asset Management Policy

# Asset Management Policy

**Policy Owner:** Paul Jones  
**Version:** 2.1  
**Effective Date:** 2021-07-06  
**Last Reviewed:** 2026-02-24  

---

## 1. Purpose

To ensure that organizational assets are identified, appropriately protected, and managed throughout their lifecycle.

---

## 2. Scope

This policy applies to:

- Information systems and infrastructure
- Cloud environments
- Source code repositories
- End-user computing devices
- SaaS platforms used to support business operations
- Data stored or processed by Crystal Project Inc

---

## 3. Definition of Assets

Assets include, but are not limited to:

- Production and development infrastructure
- Cloud accounts and services (e.g., AWS)
- Source code repositories
- SaaS applications
- Company-issued laptops and mobile devices
- Customer and internal data

---

## 4. Asset Inventory

Crystal Project maintains visibility into critical business and production assets through:

- Cloud provider account management (e.g., AWS)
- Centralized source code repositories
- Identity provider account listings
- A maintained inventory of company-issued devices
- Vendor and subprocessor documentation

Company-issued devices are tracked and periodically reviewed to ensure accountability.

The level of documentation and tracking is proportionate to organizational size and operational complexity.

---

## 5. Ownership of Assets

Each significant system or platform must have a designated responsible owner.

Owners are responsible for:

- Ensuring appropriate security controls are in place
- Reviewing access controls
- Coordinating remediation of security issues

Ownership may be assigned to an individual or a defined function.

---

## 6. Acceptable Use of Assets

All organizational assets must be used in accordance with:

- The Information Security Policy
- Employment agreements
- Applicable contractual obligations

Unauthorized use, removal, or modification of assets is prohibited.

---

## 7. Handling and Protection of Assets

Personnel issued company equipment must:

- Exercise reasonable care in protecting devices
- Prevent unauthorized access
- Secure devices when unattended
- Comply with endpoint security requirements

Mobile devices must comply with security standards defined in related policies.

---

## 8. Return or Disposition of Assets

Upon termination of employment or contract, company-issued assets must either:

- Be returned to Crystal Project, or
- Be formally transferred or disposed of with management approval.

Where devices are returned, appropriate steps must be taken to protect or remove company data prior to reuse or reassignment.

Access to digital systems must be removed in accordance with the Access Control Policy regardless of physical device disposition.

---

## 9. Exceptions

Exceptions must:

- Be documented
- Include justification
- Be approved by the Policy Owner

---

## 10. Violations and Enforcement

Violations may result in:

- Removal of system access
- Corrective action
- Disciplinary measures
- Termination of engagement where appropriate

---

## 11. Review and Revision History

| Version | Date | Description | Author |
|----------|------------|-------------|----------|
| 1.0 | 2021-07-06 | Initial Version | Kirsten Alexander |
| 2.1 | 2026-02-24 | Simplified and aligned to operational practice | Paul Jones |

### Business Continuity and Disaster Recovery (BC/DR) Policy

# Business Continuity and Disaster Recovery (BC/DR) Policy

**Policy Owner:** Paul Jones  
**Version:** 2.2  
**Effective Date:** 2021-07-06  
**Last Reviewed:** 2026-02-24  

---

## 1. Purpose

To ensure the continued availability of critical systems and services and to define recovery strategies in the event of regional, infrastructure, or operational disruptions affecting Crystal Project Inc.

---

## 2. Scope

This policy applies to:

- Production systems and infrastructure
- Customer-facing services
- Critical internal business systems
- Backup and recovery processes

Crystal Project Inc. operates as a fully remote organization and does not rely on physical office infrastructure for core business continuity.

---

## 3. Resilience Architecture

Production systems are designed for high availability within a primary AWS region.

Continuity controls include:

- Multi-Availability Zone (multi-AZ) deployment within the primary AWS region
- Automated failover at the availability zone level
- Infrastructure-as-code configuration management enabling rapid environment reconstruction
- Redundant managed services where applicable

The primary production database is deployed in a multi-AZ configuration. In the event of an availability zone failure, automated promotion of a standby replica occurs within the same region.

In the event of a regional outage, recovery is achieved through infrastructure redeployment and restoration from backups. Recovery time objectives reflect this approach.

---

## 4. Disaster Scenarios

Disruption scenarios considered within scope include:

- Availability zone failure
- Regional cloud service disruption
- Infrastructure misconfiguration
- Data corruption
- Security incidents affecting availability
- Critical SaaS provider outages

Cloud provider outages are within the scope of BC/DR planning and response.

---

## 5. Failover and Recovery

Failover procedures are designed to restore services in the event of availability zone or infrastructure disruption.

Recovery mechanisms may include:

- Automated multi-AZ failover within the primary region
- Promotion of standby database replicas
- Infrastructure redeployment via code
- Restoration from backups

Recovery capabilities are validated periodically through restore testing, tabletop exercises, or controlled simulations.

---

## 6. Backup and Data Protection

Critical production data is protected through:

- Automated cloud-native backups within the primary AWS region
- Controlled access to backup storage
- Periodic restore validation testing (at least annually)

Recovery point objectives (RPO) depend on the backup frequency and retention configuration at the time of disruption.

---

## 7. Recovery Objectives

Recovery objectives are risk-based and prioritize:

- Restoration of customer-facing services
- Protection of data integrity
- Preservation of confidentiality
- Minimization of downtime

Recovery time and recovery point objectives (RTO/RPO) are determined by system criticality and architectural design.

---

## 8. Business Operations Continuity

Core business functions rely on distributed SaaS providers (e.g., email, collaboration, CRM, finance).

Personnel operate remotely and are not dependent on centralized facilities.

Business continuity is therefore not tied to a single physical location.

---

## 9. Integration with Incident Response

Major availability disruptions are managed in coordination with the Incident Response Policy.

Post-incident reviews are conducted following material outages to identify improvement opportunities.

---

## 10. Testing and Review

Disaster recovery readiness is evaluated through:

- Restore testing (at least annually)
- Tabletop exercises
- Architecture review during significant system changes
- Post-incident analysis

This policy is reviewed at least annually.

---

## 11. Exceptions

Exceptions must be documented and approved by the Policy Owner.

---

## 12. Review and Revision History

| Version | Date | Description | Author |
|----------|------------|-------------|----------|
| 1.0 | 2021-07-06 | Initial Version | Jona Morua |
| 2.2 | 2026-02-24 | Updated to reflect active/active multi-region architecture with automated failover | Paul Jones |
| 2.3 | 2026-06-25 | Updated to reflect single-region multi-AZ architecture | Paul Jones |

### Cryptography Policy

# Cryptography Policy

**Policy Owner:** Security Team  
**Version:** 2.0  
**Effective Date:** 2021-07-06  
**Last Reviewed:** 2026-02-24  

---

## 1. Purpose

To ensure appropriate and effective use of cryptographic controls to protect the confidentiality, integrity, and authenticity of information processed by Crystal Project Inc.

This policy defines requirements for encryption, hashing, and cryptographic key management.

---

## 2. Scope

This policy applies to:

- All systems that store, process, or transmit Confidential or Customer data
- All production infrastructure
- All engineers and administrators managing cryptographic materials

---

## 3. Encryption Requirements

### 3.1 Data in Transit

All external network traffic transmitting Confidential or Customer data over public networks must use secure transport protocols.

- TLS 1.2 or higher is required
- TLS 1.3 is preferred where supported
- Weak or deprecated protocols (e.g., SSL, TLS 1.0/1.1) must not be enabled

Certificates must be issued by trusted certificate authorities and managed through approved infrastructure providers.

---

### 3.2 Data at Rest

Confidential and Customer data stored in production systems must be encrypted at rest using strong, industry-standard cryptography.

Where possible, encryption at rest is enforced through:

- Cloud provider managed encryption (e.g., AWS-managed encryption)
- Encrypted storage services (e.g., S3, RDS, EBS, etc.)
- Full disk encryption for employee laptops

---

### 3.3 Password and Credential Protection

User passwords must be stored using strong one-way hashing algorithms with salting and appropriate work factors.

Approved algorithms include:

- bcrypt
- scrypt
- PBKDF2
- Argon2 (where applicable)

Plaintext password storage is strictly prohibited.

---

## 4. Key and Secret Management

Cryptographic keys and application secrets must be:

- Access-controlled using role-based access controls
- Stored in approved secret management systems or secure environment configuration
- Not hard-coded into source code repositories
- Rotated when risk, exposure, or operational needs require it

Approved secrets management systems include AWS Secrets Manager, AWS KMS, and platform-managed secure environment configuration (e.g., Vercel environment variables). The appropriate system is selected based on secret type and sensitivity.

Access to cryptographic materials must be limited to authorized personnel only.

Where cloud-managed key services are used, provider controls are relied upon for key lifecycle management and audit logging.

---

## 5. Algorithm and Strength Standards

Crystal Project uses strong, industry-accepted cryptographic standards.

Examples include:

- AES-128 or AES-256 for symmetric encryption
- RSA-2048 or stronger for asymmetric encryption
- ECDHE for key exchange
- SHA-256 or stronger for hashing (where hashing is required)

Deprecated or insecure algorithms (e.g., MD5, SHA-1 for security-sensitive purposes, DES, RC4) must not be used.

---

## 6. Risk-Based Cryptographic Controls

Encryption and pseudonymization controls are implemented based on:

- The sensitivity of the data
- The risk to individuals and the organization
- Industry standards and regulatory requirements
- Cost and operational feasibility

Cryptographic implementations must align with current industry best practices.

---

## 7. Exceptions

Exceptions to this policy must:

- Be documented
- Include a risk assessment
- Be approved by the Policy Owner

---

## 8. Violations and Enforcement

Violations of this policy may result in:

- Removal of access
- Corrective action
- Disciplinary measures
- Termination of engagement where appropriate

---

## 9. Review and Revision History

| Version | Date | Description | Author |
|----------|------------|-------------|----------|
| 1.0 | 2021-07-19 | Initial Version | Jona Morua |
| 2.0 | 2026-02-24 | Modernized standards and cloud-aligned controls | Paul Jones |

### Data Management Policy

# Data Management Policy

**Policy Owner:** Paul Jones  
**Version:** 2.1  
**Last Reviewed:** 2026-02-24  

---

## 1. Purpose

To define how Crystal Project Inc. (“Crystal”) classifies, protects, retains, and securely disposes of information in accordance with business, contractual, and legal requirements.

---

## 2. Scope

This policy applies to:

- All data processed or stored by Crystal
- All information systems and infrastructure
- All personnel handling company or customer data

---

## 3. Data Classification

Crystal maintains three data classifications:

### Confidential

Highly sensitive information requiring the highest level of protection.

Examples include:

- Customer data
- Personally identifiable information (PII)
- Authentication credentials and secrets
- Financial and payroll data
- Incident and vulnerability reports
- Source code
- Strategic plans

### Restricted

Internal business information requiring protection but not classified as Confidential.

Examples include:

- Internal policies
- Contracts
- Internal reports
- Meeting materials
- Internal communications

Restricted is the default classification for company information unless otherwise specified.

### Public

Information approved for public distribution.

Examples include:

- Marketing materials
- Public-facing policies
- Product documentation
- Press releases

---

## 4. Data Handling Requirements

### Confidential Data

Confidential data must:

- Be accessible only to authorized personnel
- Be protected using role-based access controls
- Be encrypted in transit over public networks
- Be encrypted at rest where supported
- Be stored only in approved systems
- Be transferred externally only under appropriate contractual or legal safeguards

Production customer data is not used in non-production environments except where strictly necessary and appropriately safeguarded.

### Restricted Data

Restricted data must:

- Be accessible on a need-to-know basis
- Not allow unauthenticated or anonymous access
- Be transferred externally only with appropriate authorization

### Public Data

Public data may be freely distributed once formally approved.

---

## 5. Data Retention

Data is retained only as long as necessary to:

- Fulfill contractual obligations
- Meet legal or regulatory requirements
- Support legitimate business operations

Customer data is deleted in accordance with contractual terms, customer requests, and applicable agreements.

Legal hold requirements override standard retention timelines when applicable.

Retention practices are reviewed periodically.

---

## 6. Data Disposal

When Confidential or Restricted data is no longer required:

- It must be securely deleted or destroyed.
- Cloud-hosted data is deleted using platform-native secure deletion mechanisms.
- Devices returned to the company are wiped or reprovisioned prior to reassignment where applicable.

Third-party vendors must support secure deletion consistent with contractual obligations.

---

## 7. Backup and Replication

Production data may be replicated or backed up for resilience and disaster recovery purposes in accordance with the Business Continuity and Disaster Recovery Policy.

Backup and replicated data remain subject to the same classification and protection requirements as primary data.

---

## 8. Compliance and Review

Compliance with this policy may be verified through internal review processes and external audits where applicable.

This policy is reviewed at least annually.

---

## 9. Exceptions

Exceptions must be documented and approved by the Policy Owner.

---

## 10. Enforcement

Violations may result in corrective action, up to and including termination of employment or contract.

---

## 11. Review History

| Version | Date | Description | Author |
|----------|------------|-------------|----------|
| 1.0 | 2021-07-19 | Initial Version | Jona Morua |
| 2.1 | 2026-02-24 | Simplified and aligned to operational practice and DPA | Paul Jones |

### Human Resource Security Policy

# Human Resource Security Policy

**Policy Owner:** Kirsten Alexander  
**Version:** 2.0  
**Effective Date:** July 6, 2021  
**Last Reviewed:** 2026-02-24  

---

## 1. Purpose

To ensure that employees and contractors understand their information security responsibilities and are suitable for their assigned roles based on risk and access level.

---

## 2. Scope

This policy applies to:

- All employees of Crystal Project Inc. (Crystal Knows)
- Consultants and contractors
- Third-party personnel with access to Crystal production systems, networks, or sensitive information

---

## 3. Policy

### 3.1 Screening

Crystal Project performs background screening where appropriate and proportionate to:

- Role responsibilities
- Level of system or data access
- Sensitivity of information handled
- Identified organizational risk

Background screening may include:

- Reference checks
- Employment verification
- Criminal background checks where applicable and legally permissible

Third parties with privileged or administrative access to production systems may be subject to additional due diligence based on risk.

Screening practices are implemented in accordance with applicable laws and regulations.

---

### 3.2 Role Definition and Competence

Hiring managers define required qualifications and competencies in job descriptions.

Candidate evaluation may include:

- Interviews
- Technical assessments
- Reference checks
- Verification of education or certifications where relevant

Managers are responsible for ensuring personnel are capable of fulfilling their security responsibilities.

Performance and role effectiveness may be evaluated periodically at management’s discretion.

---

### 3.3 Terms and Conditions of Engagement

At the time of hire or engagement:

- Information security responsibilities are communicated
- Relevant policies are made available
- Employees and applicable contractors sign confidentiality agreements

Contracts with third parties define security obligations where appropriate.

All personnel are required to comply with Crystal Project information security policies for the duration of their employment or engagement.

---

### 3.4 Management Responsibilities

Management is responsible for:

- Maintaining and reviewing information security policies at least annually
- Ensuring policies are accessible to relevant personnel
- Assigning and documenting security responsibilities
- Enforcing compliance with security requirements

Information security responsibilities are documented in job descriptions, policies, or related governance materials.

---

### 3.5 Security Awareness and Training

All employees and contractors with privileged or administrative access to production systems must:

- Complete security awareness training at onboarding
- Complete security awareness training periodically thereafter

Training completion is monitored by management.

All personnel are expected to remain aware of applicable information security policies and procedures.

---

### 3.6 Disciplinary Process

Violations of information security policies may result in:

- Suspension or removal of system access
- Investigation
- Disciplinary action
- Termination of employment or contract where appropriate

Disciplinary actions are proportionate to the nature and severity of the violation.

---

## 4. Exceptions

Exceptions to this policy must:

- Be documented
- Include justification
- Be approved by the Policy Owner or designated management authority
- Define compensating controls where applicable

---

## 5. Reporting and Enforcement

Suspected violations of this policy should be reported to management or Human Resources.

Confirmed violations may result in corrective action consistent with company policies and applicable law.

---

## 6. Review and Revision History

| Version | Date | Description | Author |
|----------|------------|-------------|----------|
| 1.0 | 2021-07-19 | Initial Version | Kirsten Alexander |
| 2.0 | 2026-02-24 | Updated to align with operational practice | Paul Jones |

### Incident Response Policy

# Incident Response Policy

**Policy Owner:** Paul Jones  
**Version:** 2.1  
**Effective Date:** 2021-07-06  
**Last Reviewed:** 2026-02-24  

---

## 1. Purpose

To define how Crystal Project Inc identifies, responds to, and resolves security incidents affecting systems, infrastructure, or data.

---

## 2. Scope

This policy applies to security events or incidents involving:

- Customer data
- Production systems
- Infrastructure
- Internal systems
- Confidential information

---

## 3. Definitions

**Security Event**  
An observable occurrence related to system or data security.

**Security Incident**  
A confirmed event resulting in unauthorized access, disruption, data exposure, or compromise.

---

## 4. Reporting

All personnel must promptly report suspected security events.

Reports may be made through internal communication channels (e.g., Slack) or directly to engineering leadership.

Customers may report issues through official support channels.

---

## 5. Severity Classification

Incidents are classified based on impact:

- **Critical** – Active compromise, confirmed malicious activity, or material customer impact.
- **High** – Significant vulnerability or elevated operational risk.
- **Medium / Low** – Limited impact or suspicious activity requiring investigation.

Severity determines escalation urgency and communication cadence.

---

## 6. Response Process

When a significant incident occurs:

1. A dedicated Slack channel is created.
2. Engineering leadership coordinates response.
3. Investigation and containment actions begin immediately.
4. Systems are restored or mitigations are applied.
5. Communication is provided to leadership and, if required, customers.

A real-time huddle may be used during active incidents.

---

## 7. Roles and Responsibilities

### Policy Owner (Incident Lead)

- Coordinates response efforts
- Determines severity
- Assigns remediation tasks
- Determines incident resolution
- Evaluates notification requirements

### Engineering Team

- Investigates root cause
- Implements containment and remediation
- Restores services
- Documents findings

### Executive Leadership

- Informed of material incidents
- Participates in external communication decisions when required

---

## 8. Breach Determination and Notification

If an incident involves potential unauthorized access to customer data or regulatory impact:

- The Policy Owner, in consultation with executive leadership, determines whether notification obligations apply.
- Notifications are made in accordance with contractual and legal requirements.

---

## 9. Documentation

All confirmed incidents are documented.

Documentation includes:

- Timeline of events
- Impact assessment
- Root cause analysis (for significant incidents)
- Corrective actions

Postmortems are maintained in internal systems (e.g., Notion).

---

## 10. Post-Incident Improvement

Significant incidents are reviewed to:

- Identify systemic weaknesses
- Improve controls and detection
- Prevent recurrence

Lessons learned are incorporated into engineering and operational practices.

---

## 11. Testing and Readiness

Incident response readiness is evaluated through periodic tabletop exercises (conducted at least annually and often more frequently).

Tabletops may be combined with broader risk discussions.

---

## 12. Exceptions

Exceptions must be documented and approved by the Policy Owner.

---

## 13. Review and Revision History

| Version | Date | Description | Author |
|----------|------------|-------------|----------|
| 1.0 | 2021-07-06 | Initial Version | Jona Morua |
| 2.1 | 2026-02-24 | Simplified and aligned to operational practice | Paul Jones |

### Information Security Policy

# Information Security Policy

**Policy Owner:** Paul Jones  
**Version:** 2.0  
**Effective Date:** 2024-09-12  
**Last Reviewed:** 2026-02-24  

---

## 1. Purpose

This policy defines Crystal Project Inc’s overall approach to information security governance and establishes the framework under which specific security policies and controls operate.

The objective is to protect the confidentiality, integrity, availability, and privacy of customer data, company information, and supporting systems.

---

## 2. Scope

This policy applies to:

- All employees and contractors
- All information systems and infrastructure
- All company-controlled and customer data
- All devices used to access company systems

---

## 3. Security Governance Principles

Crystal Project maintains a pragmatic, risk-based security program appropriate to its size and operational complexity.

Security governance includes:

- Executive oversight of security risk
- Role-based access control and least privilege
- Multi-factor authentication (MFA) required for all workforce identities
- Secure software development practices
- Encryption of data in transit and at rest
- Independent third-party penetration testing performed annually
- Periodic access reviews
- Incident response readiness and tabletop exercises
- Vendor risk management
- Continuous improvement through postmortems and review

Security is a shared responsibility across the organization.

---

## 4. Responsibilities

### Policy Owner

The Policy Owner is responsible for:

- Maintaining the security program
- Reviewing policies at least annually
- Approving exceptions
- Coordinating incident response
- Communicating material risks to executive leadership

### Employees and Contractors

All personnel must:

- Follow applicable security policies
- Protect company and customer information
- Report suspected security events promptly
- Use company systems responsibly and in accordance with business purposes

---

## 5. Policy Framework

This Information Security Policy is supported by the following policies and plans:

- Access Control Policy
- Asset Management Policy
- Risk Management Policy
- Incident Response Policy
- Secure Development Policy
- Cryptography Policy
- Business Continuity and Disaster Recovery Plan
- Third-Party Risk Management Policy
- Human Resource Security Policy

These policies define specific operational requirements.

---

## 6. Monitoring and Compliance

Crystal Project may monitor systems, networks, and logs as necessary to:

- Maintain operational security
- Detect misuse or unauthorized access
- Ensure compliance with company policies

Compliance may be evaluated through internal review processes and external audits where applicable.

---

## 7. Exceptions

Exceptions to this policy must:

- Be documented
- Include justification
- Be approved by the Policy Owner

---

## 8. Enforcement

Violations of this policy may result in:

- Removal of system access
- Corrective action
- Disciplinary measures
- Termination of engagement where appropriate

---

## 9. Review and Revision History

| Version | Date | Description | Author |
|----------|------------|-------------|----------|
| 1.0 | 2021-07-19 | Initial Version | Jona Morua |
| 1.2 | 2024-09-12 | Updated for policy migration | Paul Jones |
| 2.0 | 2026-02-24 | Simplified and aligned to operational practice | Paul Jones |

### Information Security Roles and Responsibilities

# Information Security Roles and Responsibilities

**Policy Owner:** Paul Jones  
**Version:** 2.0  
**Last Reviewed:** 2026-02-24  

---

## 1. Purpose

This policy defines information security roles and responsibilities within Crystal Project Inc. (“Crystal”) to ensure accountability, clarity, and effective governance of the security program.

---

## 2. Scope

This policy applies to:

- All employees
- Contractors
- Executive leadership
- Individuals with access to company systems or data

---

## 3. Security Governance Structure

Crystal maintains a lean, engineering-led security governance model appropriate to its size and operational complexity.

Security responsibilities are distributed across leadership and operational roles as defined below.

---

## 4. Roles and Responsibilities

### Policy Owner (Chief Technology Officer)

The Policy Owner is responsible for:

- Overall security program oversight
- Maintaining and reviewing security policies
- Coordinating risk management activities
- Overseeing incident response
- Approving policy exceptions
- Reporting material security risks to executive leadership
- Ensuring alignment between security posture and business objectives

---

### Executive Leadership

Executive leadership:

- Provides oversight of enterprise risk, including cybersecurity risk
- Participates in material incident and breach decisions
- Supports resource allocation for security initiatives

---

### Engineering

Engineering is responsible for:

- Secure software development practices
- Infrastructure security and hardening
- CI/CD security controls
- Implementation of vulnerability remediation
- Operational logging and monitoring
- Supporting disaster recovery and resilience testing

Engineering leadership works with the Policy Owner to ensure security controls are embedded in development and operations.

---

### Human Resources (or Designated Leadership)

Responsible for:

- Ensuring personnel are informed of company policies
- Coordinating onboarding and offboarding processes
- Supporting background checks where applicable
- Ensuring personnel complete required security awareness training

---

### System Owners (Where Applicable)

Individuals responsible for specific systems must:

- Ensure appropriate access controls are applied
- Support risk identification and remediation
- Approve non-standard access requests where appropriate

---

### All Personnel

All employees and contractors are responsible for:

- Adhering to company security policies
- Protecting company and customer information
- Reporting suspected incidents or vulnerabilities
- Minimizing risk exposure through responsible system use

---

## 5. Policy Compliance

Compliance with this policy may be evaluated through:

- Internal review processes
- External audits where applicable
- Risk management activities

Non-compliance may result in corrective action up to and including termination.

---

## 6. Exceptions

Exceptions must be documented and approved by the Policy Owner.

---

## 7. Review History

| Version | Date | Description | Author |
|----------|------------|-------------|----------|
| 1.0 | 2021-07-19 | Initial Version | Jona Morua |
| 2.0 | 2026-02-24 | Updated to reflect current organizational structure | Paul Jones |

### Operations Security Policy

# Operations Security Policy

**Policy Owner:** Paul Jones  
**Version:** 2.0  
**Effective Date:** 2021-07-06  
**Last Reviewed:** 2026-02-24  

---

## 1. Purpose

To ensure the secure and reliable operation of production systems and supporting infrastructure used by Crystal Project Inc.

---

## 2. Scope

This policy applies to:

- Production systems and infrastructure
- Cloud environments
- Business-critical systems
- Logging, monitoring, and backup processes

---

## 3. Operational Change Management

Production changes must be implemented through approved CI/CD pipelines and version-controlled processes as defined in the Secure Development Policy.

Operational controls include:

- Automated testing prior to deployment
- Pipeline-controlled production releases
- Audit logging of changes
- Restricted direct access to production environments

Emergency changes may be implemented when necessary to restore service or mitigate risk and must be reviewed retrospectively.

---

## 4. Environment Controls

Crystal Project Inc. maintains logical separation between:

- Local development environments
- Preview or testing environments
- Production systems

Production access is restricted to authorized personnel and protected by role-based access controls and MFA.

---

## 5. Logging and Monitoring

Production systems are configured to generate logs appropriate to their function.

Logging and monitoring practices include:

- Centralized log aggregation across production systems
- Recording user and administrative activities
- Monitoring for suspicious activity
- Alerting on high-risk security events
- Protecting logs from unauthorized modification

Logs are retained for a minimum of 90 days in active storage and 12 months in archive. Retention periods may exceed these minimums based on contractual or regulatory requirements.

---

## 6. Backup and Recovery

Critical systems and production data are backed up using cloud-native backup mechanisms.

Backups:

- Run automatically on a scheduled basis
- Are protected from unauthorized access
- Are periodically validated for restore capability

User endpoint devices are not centrally backed up. Personnel are responsible for storing critical business documents in approved cloud storage systems.

---

## 7. Vulnerability Management

Technical vulnerabilities are identified through:

- Independent third-party penetration testing performed annually
- Automated dependency vulnerability scanning (continuous)
- Cloud-native monitoring tools
- External reporting (e.g., responsible disclosure)

Vulnerabilities are evaluated based on severity, exploitability, and business impact and remediated according to the following targets:

| Severity | Remediation Target |
|----------|-------------------|
| Critical | 72 hours |
| High | 14 days |
| Medium | 30 days |
| Low | 90 days |

Remediation progress against these targets is tracked by engineering leadership and reviewed as part of the security governance process.

---

## 8. Malware and Threat Protection

Company-issued devices must use operating systems with built-in security protections enabled.

Threat detection and filtering mechanisms are utilized for email and production systems where supported by platform providers.

Personnel must not disable security protections without authorization.

---

## 9. Infrastructure Hardening

Production infrastructure is configured in accordance with cloud provider best practices, including:

- Restricted network exposure
- Role-based access control
- Encrypted communications
- Minimal open ports and services
- Removal of unused accounts and permissions

Infrastructure configurations are maintained through code where feasible.

---

## 10. Audit and Review

Operational controls may be reviewed through:

- Internal review processes
- Tabletop exercises
- Post-incident reviews
- External audits where applicable

---

## 11. Exceptions

Exceptions must be documented and approved by the Policy Owner.

---

## 12. Enforcement

Violations may result in:

- Removal of system access
- Corrective action
- Disciplinary measures
- Termination of engagement where appropriate

---

## 13. Review and Revision History

| Version | Date | Description | Author |
|----------|------------|-------------|----------|
| 1.0 | 2021-07-06 | Initial Version | Kirsten Alexander |
| 2.0 | 2026-02-24 | Rewritten for CI/CD and cloud-native operations | Paul Jones |

### Physical Security Policy

# Physical Security Policy

**Policy Owner:** Paul Jones  
**Version:** 2.0  
**Effective Date:** 2021-07-06  
**Last Reviewed:** 2026-02-24  

---

## 1. Purpose

To define the physical security controls appropriate to a remote-first organization and to protect company assets and customer data from physical loss, theft, or unauthorized access.

---

## 2. Scope

This policy applies to:

- All employees and contractors
- Company-issued devices
- Work-from-home environments
- Cloud-hosted infrastructure
- Any physical equipment used to process company or customer data

Crystal Project Inc does not operate physical office locations or on-premises data centers.

---

## 3. Cloud Infrastructure Physical Security

All production systems and data are hosted in cloud environments managed by approved providers (e.g., AWS).

Physical security controls for production data centers — including facility access controls, surveillance, environmental controls, and hardware protections — are the responsibility of the cloud provider.

Cloud provider physical security assurances are reviewed as part of vendor risk management.

---

## 4. Remote Work Environment Security

Personnel are responsible for maintaining reasonable physical security of their work environment, including:

- Preventing unauthorized individuals from accessing company systems
- Securing devices when unattended
- Using screen locks and device encryption
- Avoiding exposure of sensitive information in public spaces

Work involving sensitive information should be conducted in a manner that reduces risk of shoulder surfing or unintended disclosure.

---

## 5. Device Protection

Company-issued devices must:

- Use full-disk encryption
- Require password or biometric authentication
- Be locked when unattended
- Be protected against theft or unauthorized use

Loss or theft of a device must be reported immediately in accordance with the Incident Response Policy.

---

## 6. Disposal and Reassignment of Equipment

When devices are returned to the company:

- Company data must be removed prior to reassignment or disposal.
- Devices must be securely wiped or reprovisioned before reuse.

If devices are transferred to former personnel with management approval, company access must be removed in accordance with the Access Control Policy.

---

## 7. Third-Party Physical Security

Suppliers and service providers that store or process company or customer data must maintain appropriate physical security controls.

Physical security assurances for cloud providers and critical vendors are evaluated through the Third-Party Risk Management process.

---

## 8. Exceptions

Exceptions must be documented and approved by the Policy Owner.

---

## 9. Enforcement

Violations may result in:

- Removal of system access
- Corrective action
- Disciplinary measures
- Termination of engagement where appropriate

---

## 10. Review and Revision History

| Version | Date | Description | Author |
|----------|------------|-------------|----------|
| 1.0 | 2021-07-06 | Initial Version | Kirsten Alexander |
| 2.0 | 2026-02-24 | Rewritten for remote-first, cloud-hosted model | Paul Jones |

### Risk Management Policy

# Risk Management Policy

**Policy Owner:** Paul Jones  
**Version:** 2.1  
**Effective Date:** 2021-07-06  
**Last Reviewed:** 2026-02-24  

---

## 1. Purpose

To ensure that information security and operational risks are identified, evaluated, and managed in a manner proportionate to the size and complexity of Crystal Project Inc.

---

## 2. Scope

This policy applies to:

- Information systems and infrastructure
- Customer data
- Business-critical processes
- Third-party vendors and service providers
- Software development and deployment practices

---

## 3. Risk Management Principles

Crystal Project applies a pragmatic, risk-based approach to security governance.

Risk management activities include:

- Identification of security and operational risks
- Evaluation of likelihood and impact
- Prioritization of remediation efforts
- Documentation of significant risks and treatment decisions
- Periodic review by leadership

Risk evaluation considers potential impact to:

- Confidentiality
- Integrity
- Availability
- Privacy
- Regulatory obligations
- Business continuity

---

## 4. Risk Identification Sources

Risks may be identified through:

- Annual third-party penetration testing
- Vulnerability scanning and monitoring tools
- Security incident postmortems
- Formal tabletop exercises conducted regularly (at least annually)
- Vendor risk reviews
- Software design and architecture reviews
- Operational experience and engineering judgment

Tabletop exercises are used to evaluate incident readiness, identify gaps, and improve response procedures.

---

## 5. Risk Evaluation

Identified risks are assessed based on:

- Likelihood of occurrence
- Potential operational or security impact
- Exploitability
- Exposure of customer or sensitive data
- Reputational or contractual implications

Risk scoring may be qualitative or quantitative depending on context.

Management retains discretion to adjust automated or third-party severity ratings based on contextual risk.

---

## 6. Risk Treatment

For each significant risk, one of the following responses may be selected:

- Mitigate
- Accept
- Transfer
- Avoid

Material risks and their treatment decisions are documented.

Risk remediation prioritization considers:

- Severity
- Resource availability
- Operational impact
- Customer commitments

---

## 7. Risk Review and Oversight

Risk posture is reviewed periodically by leadership.

Formal reviews may occur in conjunction with:

- Annual penetration testing
- Tabletop exercises
- Security reviews
- Audit preparation
- Strategic planning discussions

Significant risks are communicated to executive leadership as appropriate.

---

## 8. Continuous Improvement

Security incidents, tabletop exercises, and postmortems are used to:

- Identify systemic weaknesses
- Improve controls
- Update policies and procedures
- Reduce recurrence risk

Lessons learned are incorporated into operational practices.

---

## 9. Exceptions

Exceptions must:

- Be documented
- Include justification
- Be approved by the Policy Owner

---

## 10. Violations and Enforcement

Violations may result in:

- Corrective action
- Disciplinary measures
- Termination of engagement where appropriate

---

## 11. Review and Revision History

| Version | Date | Description | Author |
|----------|------------|-------------|----------|
| 1.0 | 2021-07-06 | Initial Version | Jona Morua |
| 2.1 | 2026-02-24 | Simplified and aligned to operational practice | Paul Jones |

### Secure Development Policy

# Secure Development Policy

**Policy Owner:** Paul Jones  
**Version:** 2.1  
**Effective Date:** 2022-07-05  
**Last Reviewed:** 2026-02-24  

---

## 1. Purpose

To ensure that security is integrated into the design, development, testing, and deployment of Crystal Project Inc systems and applications.

---

## 2. Scope

This policy applies to:

- All internally developed software and infrastructure
- All business-critical systems
- Any systems that process, store, or transmit Confidential or Customer data
- All engineers and contractors contributing to Crystal Project systems

---

## 3. Development Model

Crystal Project follows a continuous integration and continuous deployment (CI/CD) model.

Security controls are embedded directly into the engineering workflow through:

- Version-controlled source code
- Automated testing
- Automated security and dependency scanning
- Branch-based preview environments
- Pipeline-controlled production deployments
- Role-based production access controls

Security validation is enforced through technical controls rather than manual approval gates.

---

## 4. Source Code Management

All source code must:

- Be maintained in a centralized version control system (GitHub)
- Be attributable to an identified contributor
- Maintain full revision history
- Restrict direct modification of protected production branches via branch protection rules

All changes to production branches require peer code review and approval prior to merge. Branch protection is enforced at the platform level.

Automated dependency monitoring (Dependabot) is enabled on all production repositories. It generates pull requests for dependency updates and raises alerts for known vulnerabilities in third-party dependencies.

Access to repositories is role-based and periodically reviewed.

---

## 5. Change Management and Deployment Controls

All production changes must:

- Be committed through version control
- Pass defined automated test suites
- Pass configured CI validation checks prior to deployment
- Be deployed through approved deployment pipelines

If automated tests or CI checks fail, deployment is blocked until issues are resolved.

Manual release checklists are not required where automated controls provide equivalent or stronger validation.

Emergency changes may be deployed when necessary to restore service or mitigate security risk. Such changes must be documented and validated after deployment.

---

## 6. Testing and Security Validation

Security validation includes:

- Automated unit and integration tests
- Dependency vulnerability scanning
- Static analysis where applicable
- Infrastructure configuration validation
- Independent third-party penetration testing performed annually

Testing is integrated into CI pipelines and must pass before code reaches production.

---

## 7. Environment Architecture

Crystal Project uses:

- Local development environments for engineers
- Branch-based preview environments for feature validation
- Production environments deployed via automated pipelines

Traditional long-lived staging environments are not required where preview environments and automated test controls provide equivalent or stronger validation.

Production systems are logically separated from development workflows and protected by role-based access controls.

---

## 8. Platform and Dependency Management

Changes to core platforms, dependencies, or infrastructure components must be validated through testing and monitoring.

Vulnerabilities identified through scanning, monitoring, or penetration testing are tracked and remediated according to the severity-based SLAs defined in the Operational Security Policy.

---

## 9. Protection of Test Data

Production customer data must not be used in development or preview environments unless:

- Explicitly authorized
- Appropriately protected
- Operationally necessary

Test data must be handled in accordance with contractual and regulatory obligations.

---

## 10. Outsourced Development

External contributors must:

- Use approved development workflows
- Follow repository and deployment controls
- Be subject to the same access and security restrictions as internal engineers

---

## 11. Exceptions

Exceptions to this policy must:

- Be documented
- Include risk justification
- Be approved by the Policy Owner

---

## 12. Violations and Enforcement

Violations of this policy may result in:

- Removal of system access
- Corrective action
- Disciplinary measures
- Termination of engagement where appropriate

---

## 13. Review and Revision History

| Version | Date | Description | Author |
|----------|------------|-------------|----------|
| 1.1 | 2022-07-05 | Reference updates | Paul Jones |
| 2.1 | 2026-02-24 | Aligned with CI/CD and preview-based architecture | Paul Jones |

### Third-Party Risk Management Policy

# Third-Party Risk Management Policy

**Policy Owner:** Paul Jones  
**Version:** 2.0  
**Effective Date:** 2021-07-06  
**Last Reviewed:** 2026-02-24  

---

## 1. Purpose

To ensure that third-party service providers who access, process, store, or transmit company or customer data maintain appropriate security controls consistent with Crystal Project Inc.’s risk profile.

---

## 2. Scope

This policy applies to:

- Vendors and service providers with access to production systems
- Vendors that process or store customer data
- Critical SaaS providers supporting business operations
- Subprocessors

---

## 3. Third-Party Risk Principles

Crystal Project Inc. applies a risk-based approach to third-party evaluation.

Vendors are assessed proportionate to:

- The sensitivity of data involved
- Level of system access
- Business criticality
- Regulatory exposure

Not all vendors require the same level of review.

---

## 4. Vendor Due Diligence

Before engaging a vendor that may access or process customer data:

- Security posture is evaluated.
- Relevant certifications (e.g., SOC 2) are reviewed where applicable.
- A written agreement or contract is executed.
- Data protection obligations are defined where required.

For critical infrastructure providers (e.g., cloud hosting), reliance may be placed on publicly available security documentation and independent audit reports.

---

## 5. Subprocessor Management

Vendors that process customer data on behalf of Crystal Project Inc. are designated as subprocessors where applicable.

Subprocessors are:

- Documented
- Contractually bound to appropriate data protection obligations
- Reviewed when material service changes occur

---

## 6. Ongoing Monitoring

Third-party services are reviewed periodically based on risk and criticality.

Monitoring may include:

- Reviewing updated audit reports
- Evaluating significant vendor changes
- Reviewing security incidents impacting the vendor
- Reassessing risk during contract renewal

Formal annual reassessments may not be required for low-risk vendors.

---

## 7. Vendor Security Expectations

Third-parties that process customer data are expected to maintain reasonable technical and organizational security controls, including where applicable:

- Access control mechanisms
- Secure system development practices
- Vulnerability management
- Logging and monitoring
- Incident response capabilities
- Business continuity measures

Crystal Project Inc. does not impose uniform control requirements but evaluates vendors proportionate to risk.

---

## 8. Termination of Services

Upon termination of a vendor relationship involving customer data:

- Access must be revoked.
- Data must be returned or securely destroyed in accordance with contractual terms.

---

## 9. Exceptions

Exceptions must be documented and approved by the Policy Owner.

---

## 10. Enforcement

Violations may result in corrective action or termination of vendor relationships where appropriate.

---

## 11. Review and Revision History

| Version | Date | Description | Author |
|----------|------------|-------------|----------|
| 1.0 | 2021-07-06 | Initial Version | Jona Morua |
| 2.0 | 2026-02-24 | Simplified and aligned to operational practice | Paul Jones |

## Compliance

### Modern Slavery and Human Trafficking Policy

# Modern Slavery and Human Trafficking Policy

**Policy Owner:** Paul Jones  
**Version:** 1.0  
**Effective Date:** 2026-02-24  
**Last Reviewed:** 2026-02-24  

---

## 1. Purpose

Crystal Project Inc. (“Crystal”) is committed to acting ethically and with integrity in all business dealings. This policy sets out Crystal’s approach to modern slavery and human trafficking and supports compliance with applicable modern slavery and human rights legislation, including the UK Modern Slavery Act 2015 and similar requirements in other jurisdictions.

---

## 2. Scope

This policy applies to:

- All employees of Crystal Project Inc.
- Contractors and consultants engaged by Crystal
- Our approach to third-party service providers and supply chain relationships

---

## 3. Policy Statement

Crystal does not use forced labour, child labour, bonded labour, or any form of involuntary servitude in its operations. We do not tolerate modern slavery or human trafficking in our business or supply chains.

All personnel are employed or contracted voluntarily and in compliance with applicable labour laws. We are committed to ensuring that our operations and supply chains are free from modern slavery and human trafficking.

---

## 4. Nature of Our Operations

Crystal operates as a fully remote software company. We provide a personality-based communication insights platform (Crystal Knows) and do not:

- Manufacture physical goods
- Operate facilities involving manual labour or on-site production
- Maintain a traditional supply chain for physical products

Our workforce is composed of knowledge workers who work remotely. Employment and contractor relationships are governed by written agreements and applicable employment law. This operational model significantly limits exposure to sectors or geographies where modern slavery risks are typically higher, but we nevertheless maintain the commitments set out in this policy.

---

## 5. Third Parties and Supply Chain

Where we engage third-party service providers (e.g. cloud hosting, SaaS tools, professional services), we expect them to comply with applicable labour and human rights laws.

Crystal conducts vendor due diligence in accordance with our **Third-Party Risk Management Policy**. For vendors that present material labour or supply chain risk, we may include appropriate representations or commitments regarding modern slavery and human rights in our evaluation and contracting processes.

We do not knowingly engage suppliers or partners that use forced labour, child labour, or other forms of modern slavery.

---

## 6. Due Diligence and Risk Assessment

We assess modern slavery and human rights risk in line with the nature and scale of our operations. Given our remote-first, software-only business model, we focus on:

- Ensuring our own employment and contractor practices comply with labour laws
- Incorporating modern slavery and human rights considerations into third-party risk reviews where relevant
- Responding to customer and stakeholder requests for transparency (e.g. questionnaires, contractual clauses)

We will review and enhance our due diligence processes as our operations or regulatory expectations evolve.

---

## 7. Training and Awareness

Personnel with responsibility for procurement, vendor management, or compliance are made aware of this policy and the importance of modern slavery and human rights in our third-party relationships. Additional training or communication may be provided as needed to support compliance and best practice.

---

## 8. Reporting and Escalation

Anyone with concerns about modern slavery or human trafficking in connection with Crystal’s operations or supply chain may raise them through existing reporting channels, including management or designated compliance contacts. Reports will be taken seriously and addressed in accordance with our policies and applicable law.

---

## 9. Policy Review

This policy is reviewed periodically and updated as necessary to reflect changes in our operations, legal requirements, or best practice. The Policy Owner is responsible for ensuring the policy remains current and effective.

---

## 10. Related Documents

- **Third-Party Risk Management Policy** — Vendor due diligence and subprocessor management  
- **Human Resource Security Policy** — Employment and contractor practices  
- **Code of Conduct** — Standards of behaviour and ethical conduct  

For further information or a statement tailored to specific legislation (e.g. UK Modern Slavery Act transparency statement), please contact [security@crystalknows.com](mailto:security@crystalknows.com).

### Whistleblower Policy

# Whistleblower Policy

**Policy Owner:** Paul Jones  
**Version:** 1.0  
**Effective Date:** 2026-02-24  
**Last Reviewed:** 2026-02-24  

---

## 1. Purpose

Crystal Project Inc. (“Crystal”) is committed to lawful and ethical conduct in all aspects of its operations. This Whistleblower Policy is intended to encourage and enable employees and others to raise serious concerns internally so that Crystal can address and correct inappropriate conduct and actions. The policy provides a safe and confidential channel for reporting and protects individuals who report in good faith from retaliation.

---

## 2. Scope

This policy applies to:

- All employees of Crystal Project Inc.
- Contractors and consultants
- Any other person who wishes to report a concern about Crystal’s conduct, operations, or compliance

Concerns may relate to conduct occurring at work, in connection with Crystal’s business, or that otherwise affects Crystal’s operations, reputation, or legal compliance.

---

## 3. What to Report

You are encouraged to report concerns about:

- Violations of Crystal’s Code of Conduct or code of ethics
- Suspected violations of law or regulations that govern our operations
- Suspected fraud, financial misconduct, or misuse of company resources
- Discrimination, harassment, or other workplace misconduct
- Safety or environmental concerns
- Modern slavery, human rights, or other serious ethical concerns
- Any other conduct that you believe in good faith is wrongful, illegal, or inconsistent with Crystal’s policies or values

You do not need to have proof that a violation has occurred. A good-faith belief or reasonable suspicion is sufficient to make a report.

---

## 4. Reporting Channels

### Internal reporting

You may raise concerns with your manager, People/HR, leadership, or another trusted point of contact. Crystal will treat reports seriously and, where appropriate, investigate and take corrective action.

### Anonymous reporting (whistleblower channel)

For those who prefer to report anonymously, Crystal provides an **Anonymous Whistleblower Channel** via a confidential form. Reports submitted through this channel are handled in accordance with this policy.

**Anonymous Whistleblower Channel:** [Submit a report anonymously](https://docs.google.com/forms/d/e/1FAIpQLScnRub7EZrEXRIqR5BLu_Hk74-_C1kM8nQQTW8k2XOm95Kp2g/viewform)

You may choose whether to provide your contact details or to remain fully anonymous. Crystal does not track or store identifying information unless you voluntarily provide it. Never submit passwords or other sensitive personal credentials through the form.

---

## 5. Non-Retaliation

It is contrary to Crystal’s values for anyone to retaliate against an employee or other person who, in good faith, reports an ethics violation, a suspected violation of law, or other concern covered by this policy.

- **No retaliation:** No one may retaliate, harass, intimidate, or take adverse action against a person for making a good-faith report or for participating in an investigation. Retaliation includes termination, demotion, suspension, discrimination, harassment, or any other form of detriment.
- **Discipline for retaliation:** An employee who retaliates against someone who has reported a violation in good faith may be subject to discipline up to and including termination of employment.
- **Good faith:** This policy protects individuals who report in good faith. It does not protect individuals who make knowingly false or malicious reports. False or malicious reporting may result in disciplinary or other appropriate action.

---

## 6. Handling of Reports

Reports received through the whistleblower channel or other channels will be:

- Treated confidentially to the extent possible consistent with a fair investigation and legal obligations
- Reviewed by appropriate personnel (e.g. leadership, People/HR, or designated compliance contact)
- Investigated where warranted, in a timely and proportionate manner
- Acted upon as appropriate (e.g. corrective action, discipline, referral to authorities)

Crystal will not disclose the identity of a reporter without consent unless required by law or necessary to conduct a fair investigation. Where you have provided contact details, Crystal may follow up to request additional information.

---

## 7. External Reporting

Nothing in this policy prevents you from reporting concerns to a regulator, law enforcement, or other external body where you have a right or obligation to do so under applicable law. In some jurisdictions, whistleblowers may have additional protections or reporting avenues under law.

---

## 8. Policy Review

This policy is reviewed periodically and may be updated to reflect changes in law, best practice, or Crystal’s operations. The Policy Owner is responsible for maintaining and reviewing this policy.

---

## 9. Related Documents

- **Code of Conduct** — Expected standards of behaviour  
- **Modern Slavery and Human Trafficking Policy** — Human rights and supply chain  

Questions about this policy or how to report a concern may be directed to leadership or [security@crystalknows.com](mailto:security@crystalknows.com).

## General

### Code of Conduct

# Code of Conduct

**Policy Owner:** Paul Jones  
**Version:** 2.0  
**Last Reviewed:** 2026-02-24  

---

## 1. Purpose

Crystal Project Inc. (“Crystal”) is committed to fostering an inclusive, collaborative, and professional working environment.

This Code of Conduct defines expected standards of behavior and outlines consequences for unacceptable conduct.

---

## 2. Scope

This Code of Conduct applies to:

- All employees
- Contractors
- Leadership
- Anyone representing Crystal in a professional capacity

The Code applies during:

- All business activities
- Remote work
- Company-sponsored events
- Conferences or external events attended on behalf of Crystal
- Online and in-person communications related to Crystal business

This Code may also apply to conduct outside business activities when such behavior adversely affects the safety, well-being, or professional environment of Crystal personnel or customers.

---

## 3. Core Values

### Be Welcoming

Crystal strives to be a workplace that supports individuals of all backgrounds and identities. Discrimination based on race, ethnicity, national origin, gender, gender identity or expression, sexual orientation, religion, age, disability, socioeconomic status, or other protected characteristics will not be tolerated.

### Be Respectful

Disagreement is natural. Personal attacks, harassment, or intimidation are not acceptable. All personnel are expected to interact professionally and respectfully with colleagues, customers, and partners.

### Be Considerate

Decisions and actions affect others. Personnel are expected to act thoughtfully and in ways that support collaboration and psychological safety.

---

## 4. Expected Behavior

All personnel are expected to:

- Engage professionally and constructively
- Exercise respect in speech and conduct
- Attempt collaboration before escalating conflict
- Refrain from discriminatory, harassing, or demeaning behavior
- Report dangerous situations or violations of this Code

---

## 5. Unacceptable Behavior

The following behaviors are prohibited:

- Violence or threats of violence
- Discriminatory or hateful language
- Sexual harassment or unwelcome sexual attention
- Personal insults related to protected characteristics
- Deliberate intimidation or stalking (online or in person)
- Posting or threatening to post personal information without consent
- Inappropriate physical contact
- Advocacy of any of the above behaviors
- Retaliation against individuals who report concerns

Other conduct that would reasonably be considered inappropriate in a professional setting may also be addressed under this policy.

---

## 6. Weapons

Weapons are not permitted at company-sponsored events or business gatherings. Weapons include firearms, explosives, or other items intended to cause harm.

Personnel must comply with applicable laws at all times.

---

## 7. Reporting Concerns

Anyone who experiences or witnesses unacceptable behavior should promptly report it to:

- The Policy Owner, or
- Executive leadership

Reports will be handled discreetly and investigated appropriately.

Retaliation against any individual who reports a concern or participates in an investigation is strictly prohibited.

---

## 8. Disciplinary Action

Violations of this Code may result in disciplinary action proportionate to the severity of the conduct, up to and including termination of employment or contract.

Leadership will determine appropriate corrective action.

---

## 9. Responsibility

The Policy Owner is responsible for maintaining and enforcing this Code of Conduct.

All personnel share responsibility for upholding these standards.

---

## 10. Review History

| Version | Date | Description | Author |
|----------|------------|-------------|----------|
| 1.0 | 2021-08-23 | Initial Version | — |
| 2.0 | 2026-02-24 | Updated for legal entity alignment and remote-first model | Paul Jones |


---

# Frequently Asked Questions

## Data Protection Roles

**Q: Is Crystal Knows a data controller or processor?**

A: Crystal Knows acts as a data processor. Our customers act as data controllers. Customers determine how and why the platform is used, what data is entered, who has access, and how outputs are applied. We process data only in accordance with customer instructions and contractual terms.

**Q: Does using Crystal Knows create new controller obligations for us?**

A: Most organizations already act as data controllers for systems such as CRM, HR, ATS, and analytics platforms. Using Crystal Knows does not introduce a new category of controller responsibility beyond standard SaaS usage.

**Q: Are individuals made aware of the processing of their personal data?**

A: Yes. Customers, as data controllers, are responsible for providing appropriate notices to individuals. Crystal Knows supports this through its privacy documentation and contractual terms.

**Q: Are individuals asked to acknowledge the Privacy Notice or provide consent?**

A: Consent and acknowledgment requirements are managed by customers in their role as data controllers, based on their specific use cases and legal obligations.

## Transparency and Privacy Notices

**Q: Do we need to update our privacy notice to use Crystal Knows?**

A: Crystal Knows does not mandate that customers update their privacy notices. However, customers are responsible for meeting their own transparency obligations under applicable privacy laws. Depending on the use case, you may review your existing privacy notice to confirm it covers the relevant processing or make updates if appropriate.

**Q: Please provide details of the relevant Privacy Notice.**

A: Crystal Knows maintains a publicly available Privacy Notice covering the platform and its data processing activities. It is available at https://www.crystalknows.com/privacy

**Q: Who is responsible for informing assessment respondents?**

A: When customers use assessments, respondents voluntarily provide their information. Customers are responsible for informing respondents of the purpose of the assessment and how results will be used.

**Q: How does transparency work for prediction use cases?**

A: For prediction use cases, insights are generated from publicly available professional information and limited identifiers such as work email addresses. Customers determine how transparency requirements apply in their jurisdiction and context.

**Q: Are users informed that they are interacting with an AI system?**

A: Yes. Transparency is provided through product interfaces, documentation, and contractual terms, informing users that the system provides AI-assisted insights.

## AI System Overview

**Q: What does the Crystal Knows system do?**

A: Crystal Knows provides personality-based communication insights to help users tailor how they communicate with others in professional contexts. The system is designed for a specific use case and is not a general-purpose AI platform. It does not rank, score, or make eligibility or employment decisions.

**Q: Please describe the AI system in terms of its objective and functionality.**

A: The objective is to provide personality-based communication insights for professional contexts. At a high level: user-initiated input is provided, inference models generate insights, and outputs are presented to the user for interpretation. The system is hosted on AWS with encrypted data transmission and storage. All usage is user-initiated; the system does not execute autonomous actions. Monitoring focuses on system availability, reliability, and security rather than individual behavior.

**Q: What kind of AI or modeling does Crystal Knows use?**

A: Crystal Knows is built on a proprietary Bayesian statistical modeling framework (not a large language model). The system uses probabilistic inference to estimate likely communication and personality preferences based on observed signals and available professional information. Outputs represent likelihood-based insights and are advisory in nature. Crystal Knows does not operate as a general-purpose generative AI system, chatbot, virtual assistant, or recommendation engine, and it does not train or fine-tune large language models on customer data.

**Q: What is the AI system category?**

A: AI System: Other. Crystal Knows is based on a proprietary Bayesian statistical modeling approach rather than a large language model (LLM). Outputs represent likelihoods and confidence-weighted insights, not generated text predictions or conversational responses.

**Q: Is there human oversight? What is the level of human involvement (Human in the Loop)?**

A: All interactions with the system are initiated by human users. Outputs are advisory only and require human interpretation and action. No automated actions or decisions occur without human involvement. Human users remain fully in control of how insights are used. Crystal Knows does not perform automated decision-making or execute actions without human involvement.

**Q: Do you use our data to train or fine-tune models?**

A: No. The platform does not use customer data to train or fine-tune large language models.

**Q: What performance criteria are defined for the AI system?**

A: Performance criteria focus on system reliability, availability, stability, and aggregate accuracy of insights. The system is not evaluated based on decision accuracy, as it does not make decisions.

**Q: How was the AI system evaluated against performance criteria?**

A: Performance is evaluated through internal testing, monitoring, user feedback, and ongoing review of system behavior at an aggregate level.

## Responsible AI Practices

**Q: What responsible AI principles does Crystal Knows follow?**

A: Crystal Knows is designed around transparency about system functionality, human oversight and control, purpose limitation, avoidance of automated decision-making that impacts individuals' rights, and ongoing monitoring of system performance at an aggregate level. Documentation and references to these practices are available upon request.

**Q: Are there any ethical issues with the processing?**

A: No inherent ethical issues have been identified. The system is designed to provide advisory, assistive insights only. It does not make automated decisions, does not determine outcomes for individuals, and does not operate autonomously. Human users remain fully responsible for interpretation and use of outputs.

**Q: Is there a reporting channel for errors or ethical concerns?**

A: Yes. Users can report errors, data quality issues, or ethical concerns through established customer support.

## Data Sourcing and Use

**Q: What data does Crystal Knows process? What information is used to generate the output?**

A: Crystal Knows uses a limited subset of non-sensitive personal data: name (first and last), work email address, job title, role, professional background, and publicly available employment or education-related information when relevant. Crystal Knows does not intentionally collect, process, or rely on biometric data, genetic data, health or medical data, government identification numbers, financial or banking data, location tracking data, criminal conviction data, political opinions, religious or philosophical beliefs, trade union membership, or data concerning sex life or sexual orientation. Crystal Knows does not require or process dates of birth, salary or compensation data, performance evaluations, government identifiers, credentials or passwords, or special category personal data.

**Q: Where is data sourced from? Please provide details of the data sourcing process.**

A: Data is sourced from user-provided inputs and publicly available professional information. Data is collected through direct user interactions with the platform or derived from publicly available professional sources, subject to contractual and legal safeguards. Crystal Knows does not source sensitive personal data.

**Q: What third-party data is used to develop the AI system?**

A: Crystal Knows relies on proprietary datasets, publicly available professional information, and user-provided inputs. Third-party data providers are subject to vendor due diligence and contractual assurances regarding lawful data sourcing, data quality, and intellectual property rights. No third-party datasets are used to make binding decisions about individuals.

**Q: Has the quality of data used for development been tested and documented?**

A: Yes. Data quality considerations include relevance, purpose limitation, accuracy at an aggregate level, and ongoing monitoring for model performance and drift. Outputs are probabilistic and advisory, and the system does not claim perfect representation or completeness.

**Q: How is data accuracy maintained?**

A: Accuracy is maintained through updates driven by user input, periodic model review, and ongoing system monitoring. Updates occur as new information is provided.

**Q: Who is responsible for how we use Crystal insights?**

A: Customers are responsible for ensuring their downstream use of Crystal insights complies with applicable laws and their own privacy commitments.

**Q: Does the system contain free text fields where users could enter sensitive personal data?**

A: Yes, the system includes free-text input fields. Users are instructed not to enter sensitive personal data. The system does not require, encourage, or rely on sensitive personal data to function. Standard acceptable use and contractual controls apply.

**Q: Are prompts or inputs screened or monitored for acceptable use or abuse?**

A: The system does not perform proactive content monitoring for surveillance purposes. Standard security logging and monitoring apply to protect system integrity and prevent abuse. This approach minimizes unnecessary processing of personal data.

## Compliance and Standards

**Q: Does Crystal Knows comply with industry guidelines or codes of practice?**

A: Yes. Crystal Knows aligns with applicable data protection principles under GDPR, follows industry-standard SaaS security practices, and maintains SOC 2 Type II certification covering security controls. Crystal also follows responsible AI practices appropriate for assistive, non-decisioning systems.

**Q: Are controls in place to ensure users have appropriate rights and permissions to enter data?**

A: Yes. Controls include contractual requirements that customers act as data controllers, role-based access controls, acceptable use policies, and guidance to ensure users enter data in compliance with applicable laws and regulations.

**Q: Does Crystal Project Inc. use forced labor or engage in modern slavery practices?**

A: No. Crystal Project Inc. does not use forced labor, child labor, bonded labor, or any form of involuntary servitude in its operations. Crystal operates as a fully remote software company and does not manufacture physical goods or operate facilities involving manual labor. All personnel are employed or contracted voluntarily and in compliance with applicable labor laws. Crystal expects its third-party service providers to comply with applicable labor and human rights laws. Vendor due diligence is conducted in accordance with our Third-Party Risk Management Policy. We support responsible business practices and compliance with applicable modern slavery and human rights regulations.

## Security and Infrastructure

**Q: Do you have a SOC 2 report?**

A: Yes. Crystal Knows maintains SOC 2 Type II certification. Our latest report is available in the Compliance section of this Trust Center.

**Q: Do you undergo penetration testing?**

A: Yes. We conduct vulnerability scanning and annual penetration testing as part of our governance and monitoring. Summary and availability are listed under Compliance.

**Q: Where is our data stored? Where is the system hosted?**

A: Crystal Knows is hosted on Amazon Web Services (AWS) in the United States. AWS provides physical and environmental security controls; we apply additional application-level and organizational controls.

**Q: Does the system allow for local hosting?**

A: Local or on-premises hosting is not currently supported. The system is delivered as a cloud-based SaaS offering.

**Q: Is data transmitted or stored outside the country of origin?**

A: Data may be transmitted to and processed in the United States, subject to contractual safeguards and applicable data protection mechanisms.

**Q: Where is the disaster recovery location?**

A: Disaster recovery is implemented within AWS infrastructure in the United States.

**Q: Who can access our data? Who has access to the data?**

A: Access to customer data is restricted using role-based access controls and least-privilege principles. Authorized Crystal personnel may access data only for operational, support, or security purposes. Customers control access within their own organizations. Individuals outside the customer organization do not have access unless contractually authorized.

**Q: What is the potential impact to individuals in case of illegitimate access or loss of data?**

A: The appropriate classification is moderate impact. The system does not process financial, biometric, medical, or government identification data.

**Q: Does the system support logging and auditing of data access and changes?**

A: Yes. The system maintains logs and audit trails for data access, modification, and deletion in line with security and compliance requirements.

## Data Rights and Retention

**Q: Can you help us respond to data subject access requests? Can personal data be searched, extracted, or exported for DSAR purposes?**

A: Yes. The system supports searching and exporting relevant personal data to support data subject access requests. Bulk exports are subject to access controls and contractual limitations.

**Q: Can personal data be provided in a structured, machine-readable format?**

A: Yes. Data can be provided in commonly used structured formats such as CSV or JSON where required.

**Q: How long do you retain data? Can we request deletion? What is the retention rule for records and information?**

A: Data retention is governed by contractual terms and internal data retention policies. Data may be deleted upon request, subject to legal and operational requirements. Input or prompt data is retained only as necessary to provide the service and in accordance with these terms.

**Q: Will input or prompt data be retained? If yes, for how long?**

A: Input data is retained only as necessary to provide the service and in accordance with contractual terms and data retention policies. Data may be deleted upon request, subject to contractual and legal requirements.

## Governance and Monitoring

**Q: What governance and continuous monitoring processes are implemented?**

A: Crystal Knows maintains risk management and annual risk assessments, change management controls, vulnerability scanning and annual penetration testing, incident response procedures, vendor risk management reviews, and ongoing monitoring of system availability and security. Governance includes security monitoring, vendor management, change management, incident response, and periodic review of models and system behavior.

**Q: Have you had any significant security incidents?**

A: No significant security incidents occurred during the most recent audited period covered by our SOC 2 Type II report.


---

# Compliance Documents

The following compliance documents are available upon verified request at https://security.crystalknows.com//compliance

## SOC 2 Type II Report
Our most recent SOC 2 Type II audit report.
_Audit period: Oct 14, 2024 – Oct 13, 2025 · Issued Dec 17, 2025_

## Penetration Test Summary
Summary of our latest third-party penetration test.
_Assessment window: Apr 13 – Apr 17, 2025 · Delivered May 16, 2025_


---

# Key Legal Documents

- Privacy Policy: https://www.crystalknows.com/privacy
- Terms of Service: https://www.crystalknows.com/tos
- Data Processing Agreement: https://www.crystalknows.com/dpa