Security & Compliance

Enterprise-grade security
from day one.

Your financial data is among the most sensitive information your business holds. We built beCrystal with security as a foundation, not an afterthought.

Certifications & compliance

We hold ourselves to the standards your enterprise procurement team expects.

Certified

SOC 2 Type II Certified

Our security controls have been independently audited and certified to meet the highest standards for trust services criteria.

Certified

GDPR Compliant

Full compliance with the EU General Data Protection Regulation. Your customer data is handled according to the strictest European privacy standards.

Active

End-to-End Encryption

All data encrypted in transit using TLS 1.3 and at rest with AES-256. Keys are managed through hardware security modules with strict rotation policies.

How we protect your data

Data residency

Your data stays in the EU. We operate on infrastructure within European data centres and do not transfer data outside EU/EEA without explicit consent.

Audit trails

Every change to your data is logged with who made it, when, and why. Full immutable audit trail available on request.

Access controls

Role-based access control with SSO support. Least-privilege by default. You control who sees what.

Penetration testing

Annual third-party penetration tests with findings disclosed to customers on request. Vulnerability disclosure programme open year-round.

Need documentation?

Our full security documentation, Data Processing Agreement and sub-processor list are available on request, or linked below.