CrewCard Security FAQs
These CrewCard Security FAQs explain the safeguards described across CrewCard's platform, including data encryption, login protection, two-factor authentication, payroll security, server monitoring and backup controls.
SSL/TLS & Encryption
Controls described for protecting information while it is transmitted and stored.
2FA & Login Protection
Additional verification and temporary lockouts help reduce unauthorised access.
Multi-Factor Authentication
Additional controls are described for users with access to sensitive payroll information.
Monitoring & Backups
Server monitoring, security tooling and backup processes support platform resilience.
Security Overview FAQs
An overview of the safeguards described in CrewCard's current security information.
How does CrewCard protect user and business information?
CrewCard uses multiple security controls to protect information across its platforms. The safeguards described in CrewCard's current security information include SSL/TLS, encryption at rest, firewalls, login protection, security warning emails, two-factor authentication, multi-factor authentication, server monitoring and backup controls.
Does CrewCard use SSL/TLS?
Yes. CrewCard uses SSL/TLS to secure data transmitted between a user's browser and CrewCard's web services. A secure connection can typically be identified by https:// in the address bar and the browser's security indicator.
What is Encryption at Rest?
Encryption at Rest is used as an additional protection for data stored on hosting infrastructure and backup media. The purpose of this control is to reduce the risk of unauthorised access to stored information if physical storage media is compromised.
Where can I read CrewCard's Privacy Policy?
CrewCard's Privacy Policy is available online and explains how personal information is handled.
Account & Login Security FAQs
Security controls designed to reduce the risk of unauthorised account access.
What happens after repeated unsuccessful login attempts?
CrewCard limits repeated unsuccessful login attempts. Under the current security rules described for CrewCard accounts, four consecutive attempts are allowed and a fifth unsuccessful attempt triggers a temporary 15-minute block. This control is intended to reduce the risk of brute-force password attempts.
What are CrewCard Security Warning Emails?
CrewCard can send a security warning email when an account is accessed from a new device. The message is sent to the email address registered to the account and provides information about the sign-in. It also provides a way to change the password if the user does not recognise the activity.
Does CrewCard support two-factor authentication (2FA)?
Yes. CrewCard provides two-factor authentication that can be enabled from the relevant security settings. When active, supported users such as Admins, Superusers, Duty Managers and Crew are required to complete an additional verification step when signing in.
Payroll Security FAQs
Additional controls used for access to payroll and other sensitive financial information.
How is access to the Payroll Portal controlled?
Access to the Payroll Portal is limited to users who have been granted permission by an Administrator. This helps restrict payroll, taxation and accounting information to authorised users.
How does multi-factor authentication work in the Payroll Portal?
After entering a username and password, the Payroll Portal requires an additional six-digit verification code. The current security information states that the code can be delivered by email, SMS or an authenticator application, depending on the configured method.
Are shared Payroll Portal logins permitted?
No. The current Payroll Portal security rules are designed around individual user access. The portal allows one active login so that the same user account cannot be used concurrently in another browser or on another device.
Does the Payroll Portal automatically time out inactive sessions?
Yes. The current Payroll Portal configuration includes a maximum idle session timeout of 15 minutes. If the user remains inactive for that period, the session is automatically ended and the user must sign in again.
How long does the Payroll Portal 'Remember Me' function last?
The current Payroll Portal security information states that the Remember Me function is limited to 24 hours.
What happens after repeated invalid Payroll Portal login attempts?
The current Payroll Portal security information states that a user is locked out after four invalid password attempts. This helps reduce the risk of repeated password guessing.
How does CrewCard address Single Touch Payroll security and compliance?
CrewCard's current security information states that its affiliated payroll package, CrewPayer, supports Single Touch Payroll and has undergone extended conformance testing associated with Australian Taxation Office requirements. The payroll hosting environment is also described as being located in Australia.
Server & Infrastructure Security FAQs
Monitoring, firewall, malware protection, patching and backup controls described for CrewCard's hosting environment.
How is CrewCard's server environment monitored?
CrewCard's current security information describes regular monitoring for server availability, load spikes, spam activity and backup status. The purpose of these controls is to identify service or security issues early and support continuity of the platform.
What firewall and intrusion protection controls are used?
The hosting environment is described as using Imunify360. Its listed controls include an advanced firewall, intrusion detection and intrusion prevention features that monitor for suspicious activity and help block recognised attack patterns.
How is malware handled on the server?
Imunify360 is described as providing automated malware scanning across the server file system. Where malware is detected, the security platform can quarantine affected files as part of its protection process.
What is Proactive Defence?
The current server security information describes Imunify360 Proactive Defence as a control designed to identify and block potentially malicious executions in real time, including activity associated with previously unknown or zero-day attacks.
How are server security patches managed?
The server environment is described as using KernelCare for rebootless kernel patching. This allows certain security updates to be applied without requiring a full server reboot.
Is website reputation monitored?
Yes. The current server security information describes website reputation monitoring that checks whether the domain appears on recognised blocklists and provides notification if an issue is detected.
How are backups managed?
CrewCard's current security information states that the server is backed up and replicated to a separate server dedicated to backups. This is intended to support data protection and recovery in the event of an incident.
Where can I check network status or scheduled maintenance?
CrewCard's current security information links to a network status and maintenance service that provides updates about potential disruptions and scheduled maintenance.
No matching security FAQs found
Try a different search term or choose another topic.
Review CrewCard's privacy and service information
For more information about how personal information is handled, review the CrewCard Privacy Policy. You can also check the linked status service for network notifications and scheduled maintenance.