Security

Security at Cronwell

Updated August 2026

Cronwell reads the buyer mailboxes you grant access to, drafts what it wants to do, and sends nothing without a buyer’s approval. Below we discuss at Cronwell how access is scoped, how control and audit work, the SOC 2 Type II attestation, the email subprocessors, and three deployment options: our cloud, your cloud, or your own infrastructure.

Access control

Two grants, both administered in your identity system. Sign-in is single sign-on through your identity provider (in a Microsoft shop, an Entra enterprise app with SAML) so who can log in is governed by the same user groups your IT team already manages. Mailbox access runs through Nylas, our email processor and a Microsoft-verified publisher: your admin enables it and scopes it to a user group — the buyer mailboxes you designate, and only those, never a tenant-wide grant. Expanding later means adding buyers to the group. Setup is about 30 minutes of IT time.

From those mailboxes, the agent reads supplier correspondence to build and maintain the PO record: acknowledgments, exceptions, shipping notices, each linked to its source email as evidence.

The two grants, scoped by your own user groupsTHE TWO GRANTS, SCOPED BY YOUR OWN USER GROUPSYOUR MICROSOFT 365 TENANTPILOT BUYER GROUPTHE MAILBOXES YOU DESIGNATEEVERY OTHER MAILBOX — NOT IN SCOPEYOUR CRONWELLINSTANCEDEDICATED RESOURCES,PER CUSTOMERSSO · ENTRA APP (SAML)MAIL READ · SCOPED TO THE GROUPEXPANDING LATER = ADDING BUYERS TO THE GROUP · ABOUT 30 MINUTES OF IT
Both grants ride controls your IT team already operates.

How control works

The working unit is a ticket. The agent detects something — a silent PO line, a date change in a reply, a shipping notice — and opens a ticket with the action it proposes: the record update, the chase, the response. Everything the agent does runs through that ticket system, so every action is recorded: what changed, from what, on whose approval, with the evidence email attached, in an append-only history.

Approvals are governed by policy you set, and autonomy is tuned per workflow: routine tracking can run in auto mode, exceptions stay supervised, and the modes can shift to more autonomy as trust builds. Approved mail goes out from the agent’s own address or the buyer’s, whichever fits your rollout.

The ticket loopauto mode per workflow · exceptions supervised
Agent detectsTicket openedApproval, per your policyWrite / sendLogged with evidence

SOC 2 Type II

Cronwell completed its SOC 2 Type II audit. SOC 2 is an attestation by an independent auditor, not a self-awarded badge. The full report is available to customers and prospects through our Trust Center, which also lists 43 controls publicly.

Where your data can live

Where the data livesBest for
Cronwell CloudDedicated AWS resources per customer: private network, multi-region replication, encryption in transit and at rest, 4-hour recovery objective. Operated by CronwellMost teams; live in week one
BYOCYour own cloud account; residency and egress under your policies. Operated by Cronwell inside your boundaryStricter data-ownership requirements
On-premYour infrastructure, inside your network. Deployed and run with your ITDefense-shaped constraints where outside hosting is not an option

Sizing, patching, monitoring, and the email path in BYOC and on-prem deployments are scoped in the IT review call.

Email subprocessors

We use Nylas for email connectivity in the Cronwell Cloud option — Nylas holds ISO-27701, STAR Level I, and HIPAA compliance. The maintained subprocessor list lives on the Trust Center. In BYOC and on-prem deployments, the processing path is part of the scoping conversation.

What we never do

  • Suppliers don’t create accounts with us. There are no supplier credentials to phish because there are no supplier logins.
  • Each customer runs in an isolated instance: no shared tenancy, no cross-customer data.
  • Your data leaves on your schedule: export within 30 days of termination, deletion within 90, per our terms.

Common questions

What actually leaves our network?
The supplier correspondence in the mailboxes you grant, which is processed and stored inside the deployment boundary you chose: dedicated AWS resources per customer in Cronwell Cloud, your own cloud account in BYOC, or your infrastructure on-prem — where it doesn’t leave at all.
Can the agent send email without us?
Sending is governed by the approval policy you set: supervised workflows release mail on a buyer’s approval, and workflows you move to auto mode send within the rules you approved — every send logged in the ticket history either way, from the agent’s address or the buyer’s.
Is inbox access read-only?
Our agents also do write, but only under human approval on each outbound message. Cronwell agents never send out anything your buyers didn’t approve.
Can we self-host?
Yes. BYOC and on-prem are standard deployment options, scoped in the IT review.
Who can see the SOC 2 report?
Customers and prospects, through the Trust Center’s request gate. The report carries restricted-use terms, so it is shared, not posted.
What touches our mail besides Cronwell?
In Cronwell Cloud: Nylas for email connectivity and AWS for hosting, both named on the Trust Center. In BYOC and on-prem, the path is designed with your IT.
We’re a defense supplier. Can we use this at all?
That constraint is why BYOC and on-prem exist. Bring your IT lead and your specific requirements and we scope the deployment against them. It is the conversation we have most often with defense-adjacent manufacturers.

SourcesSOC 2 Type II report (issued Aug 2026; Security and Confidentiality; period Feb 1 – Jul 31, 2026), distributed via trust.cronwell.ai · Cronwell privacy policy §3 (mailbox access, subprocessors) · Cronwell terms (data export and deletion windows) · deployment details as scoped per customer. See also the compact attestation page, /soc2.

Walk your IT team through it

Request the report through the Trust Center, or put 30 minutes on the calendar with our CTO.
Request the report