Cresta Logo

Trust Center

Start your security review
View & download sensitive information
ControlK

Trust at Cresta

Welcome to Cresta's Trust Center. Our commitment to data privacy and security is embedded in every part of our business. Use this Trust Center to learn about our security posture and request access to our security documentation.
Our enterprise-grade security and data privacy program is designed to keep your customer data safe and secure. We rely on industry best practices, security product features, and comprehensive audits of our applications, systems, and networks to ensure that your data is always protected. Here is an introduction to Cresta’s security and data privacy practices.
Have questions? If you have additional questions about our security program please reach out to your enterprise sales representative or email security@cresta.ai

  • United Airlines
  • Hilton Grand Vacations
  • Holiday Inn Club Vacations
  • Brinks HomeTM
  • Marriott Vacations Worldwide
  • Optimum

Documents

Featured Documents

COMPLIANCEPCI DSS

Trust Center Updates

Subprocessor Notification

Copy link
Subprocessors

Effective July 20, 2026, Cresta has discontinued using Segment.

Cresta has added Anthropic as a sub-processor in the role of Natural Language API Provider.

Cresta added Cloudflare as a sub-processor for web application firewall software.

Cresta added ElevenLabs as a sub-processor for TTS (text-to-speech).

Effective August 30, 2025, Cresta has discontinued using Linear.

Effective August 8, 2025, Cresta has discontinued using Mixpanel.

Effective March 14, 2025, Cresta has discontinued using Atlassian.

Effective January 30, 2025, Cresta has discontinued using FullStory.

Cresta added GUIDEcx as a sub-processor for onboarding software.

Cresta added Cartesia AI as a sub-processor for TTS (text-to-speech).

Effective September 17, 2024, Cresta has discontinued using MosaicML.

Cresta added MosaicML as a sub-processor for LLM model inference.

Cresta added Atlassian as a sub-processor for project management / ticketing.

Cresta added Fireworks.ai as a sub-processor for LLM model inference.

Effective February 14, 2024, Cresta has discontinued using Optimizely.

Updates

General

Klue has published additional detail on the breach of their systems in a blog post here.

Cresta is in communication with all customers regarding the Klue incident. We will share additional updates if new information becomes available. Otherwise ongoing communication on this incident will be conducted with individual customers on a one-to-one basis.

Cresta is committed to transparency. Today we unfortunately have to announce that Cresta was impacted by the recent breach of market intelligence platform Klue.

We are working continuously to analyze the impact of this breach and to protect customer data. Here is what we know:

  • Beginning around June 11, attackers compromised Klue systems and stole OAuth credentials associated with customer integrations.
  • The stolen credentials were used to query connected Salesforce environments and exfiltrate CRM data from multiple organizations in an extortion campaign linked to Icarus.
  • Salesforce disabled the Klue integration to prevent additional unauthorized access.
  • Cresta's Salesforce instance is one of those that was impacted. Business contact information, contractual information, and email correspondence may have been exposed. We have not found any indication that Cresta's products or infrastructure are impacted.

We are in direct contact with Klue and Salesforce and we have engaged our internal and external incident response teams. We are committed to protecting customer information and will provide regular updates as this incident develops.

Cresta is aware of the security incident at Mixpanel, but is not affected by it. We discontinued using Mixpanel in August 2025.

Cresta is aware of the ongoing CrowdStrike incident, but is not affected by it. We are closely monitoring the situation and are staying in contact with CrowdStrike.

Third-party audits

Compliance

Cresta updated its Trust Center with new audit reports and certificates for SOC2 Type II, ISO27001/27701/42001, HIPAA and PCI DSS.

Cresta has updated its Trust Center with the 2025 red teaming report.

Cresta updated its Trust Center with new audit reports and certificates for SOC2 Type II and ISO27001/27701/42001.

Cresta updated its Trust Center with new audit reports for SOC2 Type II, ISO27001/27701 and HIPAA.

Vulnerability Notification

Vulnerabilities

Cresta is aware of CVE-2024-3094, related to malicious code being embedded in XZ Utils versions 5.6.0 and 5.6.1. Cresta does not use the affected versions.

Cresta is aware of CVE-2023-44487 also known as "HTTP/2 Rapid Reset attack", related to HTTP/2 capable web servers where rapid stream generation and cancellation can result in additional load which could lead to a Denial of Service. Mitigations were implemented to address the vulnerability.

If you think you may have discovered a vulnerability, please send us a note.
Report issue