Security

Enterprise-grade security. None of the enterprise.

Croft gives your team the security a big company demands — single sign-on, least-privilege access, approval gates for sensitive data, audit trails, encrypted backups — built into the platform, so there's nothing for anyone to wire up or get wrong. You get the guardrails; we handle the plumbing.

The principle

Everything starts locked.

On Croft, nothing is open until you open it. Apps start with access to nothing, people start with access to nothing, and your data stays private until you share it. Access is something you grant — on purpose, and on the record.

Apps start with access to nothing

A new app can't reach your data, your connected tools, or your other apps until you allow it. Nothing is over-shared by accident, and a clever prototype can't quietly become a data leak.

People see only what you share

Add someone once; they can open exactly the apps you choose, and nothing more. Someone leaves? Remove them once and they're out of everything, instantly — no orphaned logins to hunt down.

Sensitive data needs a nod

Connectors to things like payroll or your customer database can require an admin's approval before any app — or any person — is allowed to use them. Everyday tools flow; the sensitive ones have a gate.

Built into the platform

There's no security code for anyone to get wrong.

The riskiest part of any app is the login and access layer. On Croft, your apps don't contain one — Croft does it for them.

Enterprise single sign-on

One login in front of every app, with passkeys instead of passwords. Your apps never see or store credentials — so an app can't ship a broken login page, because it doesn't contain one.

Checked at the gate, not in the app

Identity and per-app access are verified before a request ever reaches your app. Your AI-built app simply reads who the verified person is; it never touches security code, so it can't get it wrong.

A record of everything

Who was added, who can open what, which data source was connected and approved — it's all logged. So the answer to "who can reach our billing data?" is a page you can pull up, not a guess.

Your ground, your data

It runs on a server that's yours — and stays that way.

Your own private server

A dedicated machine per workspace — real isolation, not a shared pool you sit in with strangers. Your neighbours can't reach you.

Encrypted, tested backups

Every change streams to encrypted, off-site storage, and we run real restore drills — a backup nobody has tested is just a hope. Every deploy is reversible in one click.

Yours to take, always

Export everything — code, database, files — and run it anywhere Docker does. Security you can trust shouldn't come with a lock on the door out.

The short version

The security enterprises demand — without the enterprise.

Big platforms can give you zero-trust access and audit trails, if you're willing to stand up the platform, wire in the identity layer, and keep a team on it. Croft gives your team the same guardrails as a setting, not a project.

The app you need is live in an afternoon, behind security you didn't have to build — and you never have to wait on IT, a developer, or another SaaS login to get it. See how it works →

FAQ

Frequently asked questions

How does Croft handle security?

Security is built into the platform. Everything starts locked — apps and people start with access to nothing — enterprise single sign-on sits in front of every app, and all access is on an audit trail. There’s no security code for an app to get wrong.

Does Croft support single sign-on (SSO)?

Yes. Every croft has enterprise single sign-on with passkeys in front of every app. Identity is checked at a gateway before a request ever reaches your app, so apps never touch passwords or credentials.

Where does my data live, and is it backed up?

On your own private server — a dedicated machine, not a shared pool — with continuous encrypted off-site backups, nightly snapshots, and one-click rollback on every deploy.

Can an app access data it shouldn't?

No. Apps start with access to nothing, and access is granted per app. Sensitive data sources can require an admin’s approval before any app or person uses them.

Can I export my data and leave?

Yes. Export everything — code, database, and files — as a single bundle that runs anywhere Docker does. No lock-in, no proprietary format.

Stake out your croft.

Your team's first app could be live before lunch.

Get your croft

7 days free, no card to start. From $24/month — cancel anytime and take everything with you.