Policies
Our security, privacy, and operational policies. Each policy is stored as Markdown in the repo for versioning and auditability.
18 policies across 3 categories
Security Center
Last Updated: 02/24/2026 Security, Data Protection & Responsible AI Overview This page summarizes Crystal Project Inc.’s (“Crystal”) approach to data protection, system security, and responsible use of AI-driven insights. Crystal provides personality-based communication insights through a purpose-built probabilistic modeling system. Security, privacy, and human oversight are foundational to the platform’s design. --…
Policies by category
Security
- Access Control Policy
To ensure that access to systems, infrastructure, and data is restricted to authorized individuals based on role and business need.
- Asset Management Policy
To ensure that organizational assets are identified, appropriately protected, and managed throughout their lifecycle.
- Business Continuity and Disaster Recovery (BC/DR) Policy
To ensure the continued availability of critical systems and services and to define recovery strategies in the event of regional, infrastructure, or…
- Cryptography Policy
To ensure appropriate and effective use of cryptographic controls to protect the confidentiality, integrity, and authenticity of information processed by…
- Data Management Policy
To define how Crystal Project Inc. (“Crystal”) classifies, protects, retains, and securely disposes of information in accordance with business, contractual,…
- Human Resource Security Policy
To ensure that employees and contractors understand their information security responsibilities and are suitable for their assigned roles based on risk and…
- Incident Response Policy
To define how Crystal Project Inc identifies, responds to, and resolves security incidents affecting systems, infrastructure, or data.
- Information Security Policy
This policy defines Crystal Project Inc’s overall approach to information security governance and establishes the framework under which specific security…
- Information Security Roles and Responsibilities
This policy defines information security roles and responsibilities within Crystal Project Inc. (“Crystal”) to ensure accountability, clarity, and effective…
- Operations Security Policy
To ensure the secure and reliable operation of production systems and supporting infrastructure used by Crystal Project Inc.
- Physical Security Policy
To define the physical security controls appropriate to a remote-first organization and to protect company assets and customer data from physical loss, theft,…
- Risk Management Policy
To ensure that information security and operational risks are identified, evaluated, and managed in a manner proportionate to the size and complexity of…
- Secure Development Policy
To ensure that security is integrated into the design, development, testing, and deployment of Crystal Project Inc systems and applications.
- Third-Party Risk Management Policy
To ensure that third-party service providers who access, process, store, or transmit company or customer data maintain appropriate security controls consistent…
Compliance
- Modern Slavery and Human Trafficking Policy
Crystal Project Inc. (“Crystal”) is committed to acting ethically and with integrity in all business dealings. This policy sets out Crystal’s approach to…
- Whistleblower Policy
Crystal Project Inc. (“Crystal”) is committed to lawful and ethical conduct in all aspects of its operations. This Whistleblower Policy is intended to…