Policies
Our security, privacy, and operational policies. Each policy is stored as Markdown in the repo for versioning and auditability.
19 policies across 3 categories
Security, Data Protection & Responsible AI Overview
Last Updated: 02/24/2026 Security, Data Protection & Responsible AI Overview This page summarizes Crystal Project Inc.’s (“Crystal”) approach to data protection, system security, and responsible use of AI-driven insights. Crystal provides personality-based communication insights through a purpose-built probabilistic modeling system. Security, privacy, and human oversight are foundational to the platform’s design. --…
Policies by category
Security
- Acceptable Use Policy
To set expectations for the acceptable use of Crystal Project Inc systems, accounts, and data, so that company and customer information stays secure.
MDPDF - Access Control Policy
To ensure that access to systems, infrastructure, and data is restricted to authorized individuals based on role and business need.
MDPDF - Asset Management Policy
To ensure that organizational assets are identified, appropriately protected, and managed throughout their lifecycle.
MDPDF - Business Continuity and Disaster Recovery (BC/DR) Policy
To ensure the continued availability of critical systems and services and to define recovery strategies in the event of regional, infrastructure, or…
MDPDF - Cryptography Policy
To ensure appropriate and effective use of cryptographic controls to protect the confidentiality, integrity, and authenticity of information processed by…
MDPDF - Data Management Policy
To define how Crystal Project Inc. (“Crystal”) classifies, protects, retains, and securely disposes of information in accordance with business, contractual,…
MDPDF - Human Resource Security Policy
To ensure that employees and contractors understand their information security responsibilities and are suitable for their assigned roles based on risk and…
MDPDF - Incident Response Policy
To define how Crystal Project Inc identifies, responds to, and resolves security incidents affecting systems, infrastructure, or data.
MDPDF - Information Security Policy
This policy defines Crystal Project Inc’s overall approach to information security governance and establishes the framework under which specific security…
MDPDF - Information Security Roles and Responsibilities
This policy defines information security roles and responsibilities within Crystal Project Inc. (“Crystal”) to ensure accountability, clarity, and effective…
MDPDF - Operations Security Policy
To ensure the secure and reliable operation of production systems and supporting infrastructure used by Crystal Project Inc.
MDPDF - Physical Security Policy
To define the physical security controls appropriate to a remote-first organization and to protect company assets and customer data from physical loss, theft,…
MDPDF - Risk Management Policy
To ensure that information security and operational risks are identified, evaluated, and managed in a manner proportionate to the size and complexity of…
MDPDF - Secure Development Policy
To ensure that security is integrated into the design, development, testing, and deployment of Crystal Project Inc systems and applications.
MDPDF - Third-Party Risk Management Policy
To ensure that third-party service providers who access, process, store, or transmit company or customer data maintain appropriate security controls consistent…
MDPDF
Compliance
- Modern Slavery and Human Trafficking Policy
Crystal Project Inc. (“Crystal”) is committed to acting ethically and with integrity in all business dealings. This policy sets out Crystal’s approach to…
MDPDF - Whistleblower Policy
Crystal Project Inc. (“Crystal”) is committed to lawful and ethical conduct in all aspects of its operations. This Whistleblower Policy is intended to…
MDPDF