Trust Center
Security, privacy, and transparency practices for Crescentic LLC and the products and capabilities it operates.
This Trust Center is maintained by Crescentic LLC to answer common questions about the security, privacy, governance, and operational practices used across Crescentic services.
The information presented here describes Crescentic’s current general practices and the controls used to support Crescentic websites, applications, products, and capabilities. Specific products may use different infrastructure, service providers, controls, or operating procedures. Where applicable, those differences are described in the relevant product documentation, privacy notice, terms, service agreement, or customer contract.
This Trust Center is provided for transparency. It is not an independent certification, audit report, service-level commitment, warranty, or legal guarantee.
01Shared responsibility
Security and privacy are shared responsibilities.
Crescentic manages the infrastructure, application controls, service providers, and operational processes used to protect information within its services.
Users are responsible for maintaining secure access credentials, protecting their devices, reviewing account activity, and using Crescentic products in accordance with applicable laws, product terms, and organizational policies.
Certain Crescentic products allow users to authorize trusted third parties to access selected information. Users are responsible for selecting appropriate representatives, granting suitable permissions, periodically reviewing authorized access, and revoking access when it is no longer required.
Crescentic clients are responsible for configuring user access, roles, integrations, retention settings, and data-handling practices for their own organizations. Clients are also responsible for determining which individuals may authorize third-party access and for establishing any additional approval, supervision, or recordkeeping requirements applicable to their organizations.
02Authentication, access, and delegated permissions
Crescentic applications use authentication controls appropriate to the product and its users. These controls may include email-based authentication, passwordless sign-in, multifactor authentication, session controls, and third-party identity providers.
Access to internal systems, administrative functionality, and customer information is restricted according to role and business need.
Where supported by the applicable platform, Crescentic uses application permissions, database access controls, Row Level Security policies, and similar technical controls to restrict information to authorized users and roles.
Certain Crescentic products allow an account owner to authorize a trusted third party—such as an accountant, advisor, attorney, executor, trustee, family member, or other representative—to access selected information or perform specified actions.
The account owner controls the permissions granted and may modify or revoke access through available product controls. Crescentic may retain records of invitations, permissions, authentication events, access activity, and revocation for security, support, compliance, and audit purposes.
Revoking access prevents future access through the Crescentic service. It may not remove information that an authorized third party previously downloaded, exported, or retained outside the platform.
Crescentic does not store user passwords in plain text and will not request a password through an unsolicited call, email, or text message.
03Payments and billing
Where a Crescentic product includes paid subscriptions or transactions, Crescentic may use Stripe or another disclosed payment-service provider to process payments, administer subscriptions, and provide billing functionality.
Crescentic does not ordinarily store complete payment-card numbers or payment-instrument credentials within its own application databases. Payment information is processed by the applicable payment provider under that provider’s security and privacy practices.
The payment services used by a particular product may be identified in its checkout process, product terms, privacy notice, or customer agreement.
04Data hosting and availability
Crescentic services operate on managed cloud infrastructure and third-party technology platforms selected according to the needs of each product.
Crescentic uses encryption in transit and at rest where supported and appropriate. Monitoring, logging, access controls, backups, and operational procedures are used to help detect, investigate, and respond to security and service events.
Availability commitments, maintenance practices, data residency, backup procedures, recovery objectives, and retention arrangements may vary by product and service plan.
Any contractual service level, recovery commitment, or availability guarantee will be stated in the applicable customer agreement or product documentation.
05Cookies and tracking
Crescentic websites and applications may use cookies and similar technologies for authentication, security, user preferences, analytics, performance, and functionality.
The cookies and technologies used may vary by product and website.
Users can review available choices and manage applicable preferences through the Cookie & Privacy Preferences page or through the consent controls presented within the relevant website or application.
06Third-party services and authorized recipients
Crescentic products may rely on third-party providers for infrastructure, authentication, communications, payments, analytics, artificial intelligence, email connectivity, customer support, and other operational functions.
Crescentic service providers are permitted to process information only for the services they perform for Crescentic, subject to applicable agreements and legal requirements.
The third-party services used by a particular Crescentic product may differ. Material providers may be identified in the applicable privacy notice, product documentation, customer agreement, or subprocessor disclosure.
Individuals or organizations invited by a user to access information are authorized recipients selected by that user. They are not necessarily Crescentic service providers.
An accountant, advisor, attorney, executor, trustee, or other trusted representative may have independent professional, contractual, regulatory, or legal responsibilities concerning information accessed through a Crescentic product.
Crescentic is responsible for the operation of its access-control capabilities. Crescentic is not responsible for an authorized recipient’s independent use, storage, disclosure, or retention of information outside the Crescentic platform, except as otherwise required by law or expressly agreed in writing.
07Vulnerability reporting
If you believe you have discovered a security vulnerability affecting a Crescentic product or service, contact:
Please provide sufficient information for Crescentic to reproduce, evaluate, and investigate the issue.
Do not access, alter, retain, or disclose information belonging to another user. Do not publicly disclose a suspected vulnerability before Crescentic has had a reasonable opportunity to investigate and address it.
08Privacy requests
To exercise applicable privacy rights, request access or deletion, or ask questions about Crescentic’s handling of Personal Information, contact the Crescentic Privacy Office:
If you use a Crescentic product through an employer, advisor, financial institution, issuer, service provider, or other Crescentic client, that organization may control the relevant account information.
Requests concerning information controlled by that organization should generally be directed to the organization first. Crescentic will assist its clients with privacy requests where required by contract or applicable law.
09Legal, policy, and product disclosures
The following corporate disclosures describe Crescentic’s general policies and practices:
- Privacy Statement
- Website Terms of Use
- Cookie & Privacy Preferences
- Accessibility Statement
- Human Rights & Anti-Slavery Statement
Additional disclosures may apply depending on the Crescentic product, service, or capability being used, including:
- Product Privacy Notices
- Product Terms of Service
- SMS Messaging Terms
- Subscription or Billing Terms
- Artificial Intelligence Disclosures
- Delegated-Access and Trusted-Party Terms
- Financial, digital-asset, or token-related disclosures
- Enterprise customer agreements
- Data Processing Addenda
- Security schedules
- Subprocessor disclosures
- Product-specific accessibility information
Delegated trusted-party access is a capability within certain Crescentic products and is not necessarily offered as a separate product or subscription. The privacy notice and terms applicable to the relevant Crescentic product describe how trusted-party access operates.
The Crescentic SMS Policy and any product-specific SMS Messaging Terms apply only to products that offer text-message communications.
WABLCoin and any other digital-asset or token-based offering are governed by the product-specific terms, risk disclosures, eligibility requirements, privacy notices, and other disclosures applicable to that offering.
Informational materials in this Trust Center do not independently create contractual commitments. Binding obligations are established through the terms, agreements, notices, and contracts expressly applicable to the relevant product, service, or customer relationship.
Where a product-specific notice or agreement conflicts with a general Crescentic policy, the product-specific notice or agreement controls with respect to the applicable product or service.
10Changes to this page
Crescentic may update this Trust Center to reflect changes in its products, practices, service providers, infrastructure, or legal obligations.
The revision date will be updated when changes are published.
Where appropriate, material changes affecting user rights, security commitments, or the handling of Personal Information will be communicated through the applicable legal, account, product, or customer-notification channel.
11Contact
Crescentic LLC
Security inquiries and vulnerability reports: security@crescentic.ai
Privacy questions and privacy-rights requests: privacy@crescentic.ai
Account, billing, and product support: support@crescentic.ai
Formal legal notices should be delivered in accordance with the notice provisions of the applicable Crescentic or product-specific agreement.
Crescentic’s registered-agent information is reserved for service of process and official legal notices. The registered-agent address is not a customer-support, privacy-request, or security-reporting channel.