Trust & data handling

The people in this system didn't choose to be measured.

Their employer did. That asymmetry is the reason this page exists, and the reason the platform is built the way it is. What follows is a plain description of how employee data is handled — including the parts that aren't finished.

Four lines we hold

Measurement is arithmetic. Advice is drafted. People decide.

No model scores, ranks, bands or decides anything about a person. Assessment scoring is deterministic arithmetic. AI drafts development suggestions and narrative, which a human reads, edits and accepts — and every accepted item records who accepted it and whether it was AI-drafted.

Results are walled off from decisions.

During an organization's pilot phase, assessment results are for development only. Manager views deliberately show state and follow-through — what is waiting, what has gone quiet — never element scores or fit ratings. Those live with the individual and, in development framing, on the planning surfaces.

Recognition is celebration, not evidence.

Peer recognition never feeds a rating, a ranking or a fit read, and the platform contains no leaderboard by design. Who gets thanked tracks proximity and similarity as much as contribution, and that is not a signal worth deciding anything on.

The record outlives the tool.

Every administrative action is audit-logged — currently 38 distinct event types, including exports of the audit trail itself. A compliance surface whose own use cannot be audited would fail its own standard.

The specifics

What we collect

  • Identity and employment context: name, work email, role, reporting line, optional start date.
  • Assessment responses and derived provisional scores, with an explicit consent record capturing the timestamp, policy version and instrument version.
  • Review and development content: self and manager ratings, written rationales, aspirations, commitments and check-ins.
  • Credentials, including any proof document an employee chooses to upload.

Who processes it

  • Neon (database) and Vercel (hosting and file storage) — United States.
  • Clerk for authentication; Resend for transactional email; Stripe for billing. Card details never touch Crucible systems.
  • Anthropic, for AI-drafted development suggestions and job-analysis drafts. First name, strength names, and the employee's own narrative may be sent; surname, email, identifiers, numeric scores, ratings and proof documents are never sent.
  • A current subprocessor list is provided with our Data Processing Agreement.

How long we keep it

  • While someone is employed, their records remain available to them and to the people entitled to see them.
  • When they leave, access ends immediately but records are retained for a window the customer sets — 24 months by default, adjustable between 6 and 84.
  • After that window, records become eligible for purge. Purge is a deliberate administrative act, never an automatic timer.
  • A purge irreversibly deletes assessments, reviews, recognition received, notifications, credentials and uploaded proof files.

What a purge deliberately keeps

  • The audit trail — an audit log that can be deleted is not an audit log.
  • Job-analysis contributions with the panellist's identity removed, because those document a role and every fit rating traces back to them.
  • Recognition the person gave to others, because it belongs to the recipient.
  • A tombstone record so historical references still resolve, with name and email replaced and the authentication link permanently severed.

Controls in place

  • Access is enforced on the server for every request, never by hiding interface elements.
  • Every query is scoped to a single organization; a record in another organization is indistinguishable from one that does not exist.
  • Managers see their own reporting line only — not peers, and not element scores.
  • Uploaded credential proof is stored privately and streamed through an authenticated request. Only the employee and HR can open it — deliberately not the person's manager.
  • Private recognition is excluded from every management surface, honouring the promise made where it was written.
  • Assessment item content and scoring keys never leave the server.
  • Email carries pointers, not content: no rating, score or manager comment is ever sent by email.
  • Uploads are restricted to documents and images by allow-list, and every data export defuses spreadsheet formula injection.

Independent backend, frontend and security reviews were completed before launch and their findings remediated. We'll share that documentation with a prospective customer on request.

What we don't have yet

A trust page listing only strengths is marketing. These are the gaps a diligence process would find, so here they are first:

  • We do not hold SOC 2 or ISO 27001 certification. We are a small company and will say so rather than imply otherwise.
  • Self-service data export — for an individual exercising portability, or a customer leaving — is not built yet. Requests are currently handled manually.
  • Formal error tracking and uptime monitoring are not yet in place.
  • Backup and restore procedures are provider-default and have not yet been documented or tested end to end.

Questions, or a diligence review?

We'll answer a security questionnaire, walk an architecture review, or provide our Data Processing Agreement and subprocessor list. Ask directly — you'll get the founder, not a form.