CRS Trust Center
Trust Built Every Claim We Support
CRS Temporary Housing, Inc. (CRS) supports insurers when they need it most. Protecting claim information, personal data, and the systems that enable temporary housing and managed repair services is fundamental to that responsibility.
- SOC 2 Type II examined
- NIST cybersecurity framework 2.0 aligned
- Security and controls
- Formal privacy, incident response, resilience, and third- party risk programs
| To request security documents, contact our security team, or submit a privacy inquiry email us.
Security and Trust Overview
CRS operates in a position of trust within the insurance claims process. Insurers and Policyholders rely on us to coordinate temporary housing and managed repairs while protecting the information needed to deliver those services.
Our cybersecurity program uses a risk-based approach informed by the NIST Cybersecurity Framework 2.0. Governance, risk assessment, workforce safeguards, access management, data protection, monitoring, incident response, resilience, and third-party oversight work together as a coordinated program.
CRS’s controls are independently assessed through a recurring SOC 2 Type II examination. We continually evaluate our program as our services, technology, risks, and client expectations evolve.
- Executive oversight and defined accountability
- Risk-based administrative, technical, and physical safeguards
- Security awareness and confidentiality training
- Independent assessments and recurring control monitoring
- Coordinated incident response and recovery planning
| Request Security Documents
SOC 2 Type II
CRS completed an independent SOC 2 Type II examination of the Temporary Housing Placement Services System for the period April 1, 2025, through March 31, 2026.
The examination addressed the suitability of the design and operating effectiveness of controls relevant to the AICPA Trust Services Criteria for Security and Confidentiality. The system description includes the core processes and systems supporting CRS’s temporary housing placement and Managed Repair Program services.
The independent service auditor concluded that, in all material respects, the system description was fairly presented and the controls were suitably designed and operated effectively during the examination period, subject to the dependencies, responsibilities, and inherent limitations described in the report.
The complete report is restricted to qualified clients, prospective clients, business partners, regulators, and their authorized advisors with an appropriate business need.
- Report type: SOC 2 Type II
- Review period: April 1, 2025 – March 31, 2026
- Criteria in scope: Security and Confidentiality
- Services described: Temporary Housing Placement and Managed Repair
| Request SOC 2 Report
Privacy and Data Protection
CRS processes personal, claim, housing, repair, and business information to provide services for insurers and Policyholders. We use information for authorized business purposes and protect it in accordance with applicable law, contractual commitments, and our internal privacy and data-governance requirements.
Our privacy program applies safeguards throughout the information lifecycle, including collection, use, access, sharing, retention, and secure disposition. Access is limited according to business need, and personnel receive privacy and confidentiality training.
CRS evaluates service providers that may handle protected information and establishes contractual expectations appropriate to the services and data involved. Privacy questions and requests are directed to CRS’s Data Privacy Officer.
- Purpose-based collection and use
- Data classification and handling requirements
- Role-based access and confidentiality obligations
- Retention and secure disposition
- Privacy review of relevant service providers
| Read the CRS Privacy Policy | Submit a Privacy Inquiry
Business Continuity and Catastrophe Resilience
CRS’s clients depend on our services during disruptive events, including periods of elevated claim volume. We maintain business continuity and disaster recovery capabilities designed to support critical operations, communications, and service restoration.
Our plans define responsibilities, escalation paths, recovery priorities, and coordinated response activities. CRS reviews and exercises its plans and uses lessons learned to strengthen preparedness.
Operational resilience also includes workforce readiness, backup and recovery processes, service-provider coordination, and scalable catastrophe-response procedures.
- Documented continuity and disaster recovery plans
- Defined response roles and escalation
- Exercises and plan maintenance
- Backup, restoration, and critical-service recovery
- Catastrophe-volume preparedness and partner coordination
| Request the Business Continuity Executive Summary
Incident Response and Client Notification
CRS maintains a documented incident response program designed to identify, assess, contain, investigate, remediate, and recover from security and privacy events.
The program establishes cross-functional responsibilities and escalation to appropriate leadership. CRS tests its incident response capabilities and updates plans based on exercises, operational experience, and changing risks.
When an event affects client or personal information, CRS coordinates notifications in accordance with applicable law and contractual commitments. Security concerns can be reported through the contact channel below.
- Documented response and escalation procedures
- Cross-functional security, privacy, legal, technology, and business coordination
- Exercises and continuous improvement
- Client and regulatory notification based on applicable obligations
| Report a Security Concern
Data Security and Retention
CRS protects information according to its sensitivity, business purpose, and applicable obligations. Safeguards are applied across collection, transmission, processing, storage, backup, and disposition.
CRS uses encryption to protect sensitive information in transit and at rest, limits access based on authorized business need, and monitors relevant systems and services. Retention requirements are established based on legal, regulatory, contractual, and business needs. Information that reaches the end of its approved lifecycle is securely disposed of using defined processes.
- Data classification and handling standards
- Encryption in transit and at rest, as appropriate
- Access controls and monitoring
- Backup and recovery safeguards
- Requirements-based retention and secure destruction
| Request SOC 2 Report
Identity and Access Management
CRS manages access to systems and information according to job responsibilities, authorized business need, and least-privilege principles.
Access requests and changes are subject to authorization. Privileged access is restricted, authentication safeguards are applied based on risk, and access is reviewed periodically. CRS uses multifactor authentication as part of its protection for remote access and other applicable access scenarios.
Workforce access is updated as roles change and removed through established offboarding procedures when access is no longer authorized.
- Role-based access and least privilege
- Authorized provisioning and access changes
- Multifactor authentication for applicable access
- Restricted privileged access
- Periodic review and lifecycle management
| Request SOC 2 Report
Application and Cloud Security
CRS uses cloud services and business applications to support temporary housing, managed repair, analytics, communications, and client-facing capabilities.
Security requirements are incorporated into system configuration, application development, change management, and service-provider oversight. Changes are documented, tested, authorized, and reviewed before production deployment according to risk and defined procedures.
CRS performs vulnerability management activities and periodic security testing to identify and address risk. Relevant systems are monitored, and security issues are prioritized based on potential impact.
- Secure configuration and change governance
- Separation of development and production activities
- Vulnerability management and security testing
- Monitoring and response
- Risk-based cloud and application-provider oversight
| Request SOC 2 Report
Third-Party and Housing-Provider Risk
CRS relies on a network of technology providers, hotels, landlords, housing partners, and managed repair providers to support policyholders and insurers. Third-party risk is managed according to the nature of the relationship, the services provided, and the information or systems involved.
CRS applies risk-based due diligence, contractual expectations, confidentiality requirements, and ongoing oversight to relevant service providers. Information sharing is limited to what is appropriate to perform authorized services.
For managed repair services, CRS coordinates work through qualified providers and maintains operational requirements intended to support quality, accountability, and appropriate handling of claim and policyholder information.
- Risk-based onboarding and due diligence
- Contractual security and confidentiality requirements
- Data-access and information-sharing limitations
- Monitoring of key service providers
- Operational qualification and accountability for service partners
| Request Third-Party Risk Overview
AI and Data Governance
CRS evaluates artificial intelligence and data-enabled capabilities through governance designed to address business value, security, privacy, data quality, third-party risk, legal obligations, and human accountability.
AI-enabled capabilities remain subject to CRS’s existing access control, change management, vendor risk, confidentiality, and data-protection requirements. Use cases are evaluated according to their purpose and potential impact, and appropriate human review is maintained for consequential business decisions.
CRS continues to evolve its governance as AI capabilities, risks, and regulatory expectations change.
- Business ownership and risk review
- Security and privacy assessment
- Data-use and third-party considerations
- Human accountability and oversight
- Ongoing monitoring of legal and risk developments
Payment and Financial-Data Protection
CRS processes payment and financial information needed to coordinate temporary housing, lodging, managed repairs, vendor payments, billing, and insurer reimbursement.
CRS applies access restrictions, data-protection measures, approved business processes, monitoring, and reconciliation controls appropriate to the information and transaction involved. Payment and financial information is handled in accordance with applicable legal, contractual, and business requirements.
CRS continually evaluates opportunities to minimize exposure to payment data and strengthen the systems and processes that support financial transactions.
- Need-based access to financial information
- Protected transmission and storage where applicable
- Defined authorization and reconciliation processes
- Monitoring and issue escalation
- Risk-based oversight of payment service providers
| Submit Payment-Security Question
Security Documents and Assessments
CRS makes selected security, privacy, and resilience information available to qualified clients, prospective clients, regulators, and authorized advisors. Some materials are public; sensitive assurance documents require a verified business need and acceptance of confidentiality requirements.
Available materials may change as assessments are renewed and documents are updated.
| Start a Security Review | Request Security Documents
Security and Privacy FAQ
- What does CRS’s SOC 2 Type II report cover?
The report covers CRS’s Temporary Housing Placement Services System for April 1, 2025, through March 31, 2026, and addresses the AICPA Trust Services Criteria relevant to Security and Confidentiality. The system description includes the core processes supporting temporary housing placement and managed repair services. - Is CRS SOC 2 certified?
SOC 2 is an independent attestation examination rather than a certification. CRS completed a SOC 2 Type II examination, and the independent service auditor expressed an opinion on the design and operating effectiveness of the controls in scope. - Can I download CRS’s complete SOC 2 report?
The complete report contains sensitive and restricted information. Qualified clients, prospective clients, regulators, and authorized advisors may request access for a legitimate business purpose and may be required to accept confidentiality terms. - Is CRS NIST certified?
NIST does not certify organizations against the Cybersecurity Framework. CRS uses the NIST Cybersecurity Framework 2.0 as a risk-management reference to organize and improve cybersecurity governance and outcomes. - Does CRS encrypt information?
CRS uses encryption to protect sensitive information in transit and at rest, together with access controls, monitoring, and other safeguards. - Does CRS use multifactor authentication?
CRS uses multifactor authentication as part of its protection for remote access and other applicable access scenarios. Authentication requirements are applied based on system and access risk. - Does CRS perform vulnerability scanning and penetration testing?
CRS performs vulnerability-management activities and periodic security testing. Additional assurance information may be available to qualified clients through the restricted document-request process. - How does CRS respond to security incidents?
CRS maintains documented incident response and escalation procedures, tests its response capabilities, and coordinates client or regulatory notification in accordance with applicable law and contractual obligations. - How long does CRS retain data?
Retention is based on applicable legal, regulatory, contractual, and business requirements. CRS uses defined processes for secure disposition when information reaches the end of its approved lifecycle. - How does CRS manage third-party risk?
CRS applies risk-based due diligence, contractual requirements, confidentiality expectations, and monitoring to relevant technology and operational service providers. - How does CRS govern AI?
CRS evaluates AI use cases for business purpose, security, privacy, data quality, third-party risk, legal obligations, and appropriate human accountability. - How can I report a security or privacy concern?
Use the Security Concern or Privacy Inquiry form in this Trust Center. Requests are routed to the appropriate CRS security or privacy personnel.
| For questions about CRS Trust Center, request security documents, or make a privacy inquiry email us.