Security, privacy & procurement
Everything your DPO, security, and procurement teams need to assess Complicer — in one place. Our Article 28 data processing terms, the complete subprocessor list, where your data lives, how long we keep it, and the controls that protect it. No certification we don't hold, no claim we can't back.
Data residency
EU — Frankfurt
Evidence retention
7 years
Subprocessors
9 named
DPA
Under counsel review
Data Processing Agreement (Art 28 GDPR)
When you run audits with Complicer, you are the data controller and Complicer acts as your data processor under Article 28 of the GDPR. Standard DPA under counsel review. Procurement review package available via [email protected]. An approved DPA will be executed before any customer processing begins.
- Processing only on documented instructions from you, the controller
- Confidentiality commitments for all personnel with access
- Article 32 technical and organisational measures (see controls below)
- Subprocessor transparency and prior-notice of changes (list below)
- Assistance with data-subject requests, and breach notification without undue delay
- Your choice of return or deletion of data at the end of the engagement
- Transfers to US-based subprocessors (Anthropic, Stripe, Resend, Inngest, PostHog, Upstash, Sentry, and Cloudflare edge processing) — vendor agreements and transfer mechanisms, including Standard Contractual Clauses, are under counsel review; EU-region processing is our current operating posture
Enterprise plans include custom DPA terms — email [email protected].
Subprocessors
The third parties we rely on to deliver Complicer, what each one is used for, where your data is processed, and exactly what flows to them. We notify customers before adding or changing a subprocessor.
| Subprocessor | Purpose | Data location | What we share |
|---|---|---|---|
| Fly.io | Application hosting, compute, and managed PostgreSQL database — our primary processor | European Union — Frankfurt, Germany (fra); data at rest in the EU | All application data: accounts, websites, audits, findings, and evidence. This is where your data lives. |
| Cloudflare | DNS, reverse proxy, WAF/DDoS protection (transit only), and R2 object storage for sealed evidence | Edge: global transit network. R2 evidence storage: EU jurisdiction (verified) | Request metadata in transit (IP addresses, headers, URLs); sealed evidence bundles at rest in R2. |
| Anthropic | AI classification of cookie purposes and AI-assisted remediation text | United States | Cookie names and domains, tracker signals, policy-text excerpts. No customer-site visitor data by design, and no account credentials or payment data. The AI never makes the final compliance decision — deterministic guardrails override it. |
| Stripe | Subscription billing and payment processing | United States (Stripe Inc.); EU entity available (Stripe Payments Europe Ltd, Ireland) | Billing contact and subscription tier. Payment card data is handled entirely by Stripe — Complicer never sees or stores card numbers. |
| Resend | Transactional email delivery (audit notifications, invites, scheduled summaries) | United States | User names and email addresses; notification content (audit titles, site names). Scheduled summaries carry compliance scores and result summaries. No sealed evidence files. |
| Inngest | Background-job orchestration — the event bus for the audit pipeline | United States | Event payloads: organization/audit/user identifiers, audited website URLs, recipient email addresses on notification events. No evidence files and no credentials. |
| PostHog | Product analytics — feature usage and funnel measurement | United States | Events keyed by user/organization identifiers, including audited website URLs, audit identifiers, risk/scan scores, and finding counts; marketing funnel events can include a lead’s email address. No session recording. |
| Upstash | Redis-backed rate-limit counters (abuse protection on public and expensive endpoints) | United States | Short-lived rate-limit counters keyed by user/organization identifiers and client IP addresses, expiring within minutes. No audit content. |
| Sentry | Error monitoring for the application and background jobs | United States | Error telemetry: stack traces and request metadata (URLs, IP addresses, user identifiers where available). No evidence files. |
Fly.io
- Purpose
- Application hosting, compute, and managed PostgreSQL database — our primary processor
- Data location
- European Union — Frankfurt, Germany (fra); data at rest in the EU
- What we share
- All application data: accounts, websites, audits, findings, and evidence. This is where your data lives.
Cloudflare
- Purpose
- DNS, reverse proxy, WAF/DDoS protection (transit only), and R2 object storage for sealed evidence
- Data location
- Edge: global transit network. R2 evidence storage: EU jurisdiction (verified)
- What we share
- Request metadata in transit (IP addresses, headers, URLs); sealed evidence bundles at rest in R2.
Anthropic
- Purpose
- AI classification of cookie purposes and AI-assisted remediation text
- Data location
- United States
- What we share
- Cookie names and domains, tracker signals, policy-text excerpts. No customer-site visitor data by design, and no account credentials or payment data. The AI never makes the final compliance decision — deterministic guardrails override it.
Stripe
- Purpose
- Subscription billing and payment processing
- Data location
- United States (Stripe Inc.); EU entity available (Stripe Payments Europe Ltd, Ireland)
- What we share
- Billing contact and subscription tier. Payment card data is handled entirely by Stripe — Complicer never sees or stores card numbers.
Resend
- Purpose
- Transactional email delivery (audit notifications, invites, scheduled summaries)
- Data location
- United States
- What we share
- User names and email addresses; notification content (audit titles, site names). Scheduled summaries carry compliance scores and result summaries. No sealed evidence files.
Inngest
- Purpose
- Background-job orchestration — the event bus for the audit pipeline
- Data location
- United States
- What we share
- Event payloads: organization/audit/user identifiers, audited website URLs, recipient email addresses on notification events. No evidence files and no credentials.
PostHog
- Purpose
- Product analytics — feature usage and funnel measurement
- Data location
- United States
- What we share
- Events keyed by user/organization identifiers, including audited website URLs, audit identifiers, risk/scan scores, and finding counts; marketing funnel events can include a lead’s email address. No session recording.
Upstash
- Purpose
- Redis-backed rate-limit counters (abuse protection on public and expensive endpoints)
- Data location
- United States
- What we share
- Short-lived rate-limit counters keyed by user/organization identifiers and client IP addresses, expiring within minutes. No audit content.
Sentry
- Purpose
- Error monitoring for the application and background jobs
- Data location
- United States
- What we share
- Error telemetry: stack traces and request metadata (URLs, IP addresses, user identifiers where available). No evidence files.
Your application data lives in the EU (Fly.io, Frankfurt). Some subprocessors involve US data flows — Anthropic for AI classification; Stripe, Resend, and Cloudflare for billing, email, and edge proxying; and Inngest, PostHog, Upstash, and Sentry for job orchestration, analytics, rate limiting, and error monitoring. Transfer mechanisms for these vendors, including Standard Contractual Clauses, are under counsel review — none is an executed record yet; EU-region processing is our current operating posture. The Anthropic transfer is limited to the signals needed for classification, and the AI never issues a final compliance verdict — read how our methodology keeps deterministic guardrails in control.
EU data residency
Complicer is EU-by-default. Your application data — accounts, websites, audits, findings, and evidence — is stored and processed on Fly.io in the Frankfurt region (fra), inside the European Union. Every organization carries a data-region setting that defaults to EU.
AI classification is performed by Anthropic in the United States — only the minimal signals needed (cookie names and domains, tracker and policy signals) are sent, never your credentials, billing data, or raw evidence files. Supporting services with US data flows — job orchestration, analytics, rate limiting, error monitoring, email, and billing — are named in the subprocessor list above, each with exactly what it receives. Hosting and DNS sit behind a Cloudflare proxy in front of Fly.
Retention & deletion
We keep data only as long as it serves your compliance evidence trail, then delete it.
Evidence retention
- Evidence is immutable and retained for 7 years by default
- Each artifact is SHA-256 checksummed and Ed25519-signed, with optional RFC 3161 trusted timestamping
- Locked evidence is protected from deletion (WORM-style)
- Retention supports the multi-year defensibility a regulator inquiry needs
Deletion timelines
- Expired evidence is purged automatically by a scheduled cleanup job
- Demo and trial data, idempotency keys, and MFA tokens are pruned on the same job
- On account closure, we return or delete your data at the end of the engagement
- Deletion requests are honoured subject to legal-hold and the DPA terms
Security controls
The Article 32 technical measures referenced in the DPA. Every item here maps to something that actually ships in the product.
Tamper-evident audit log
- Every audit-relevant action is written to a hash-chained log
- SHA-256 content hash linked to the previous entry (previousHash)
- Chain written inside a Serializable transaction
- verifyAuditLogChain() fails closed on any unchained entry
Immutable signed evidence
- Ed25519 signatures on evidence manifests
- SHA-256 checksums on every evidence artifact
- Optional RFC 3161 trusted timestamps (e.g. FreeTSA) on manifests, with a local-timestamp fallback
- WORM-style lock prevents deletion of locked evidence
Encryption
- TLS in transit for all connections
- Jira and integration credentials encrypted with AES-256-GCM at rest
- API keys stored as SHA-256 hashes, compared in constant time
- Webhook signatures verified (Stripe, inbound payloads)
Authentication & access
- Email + bcrypt-hashed passwords, optional TOTP MFA
- MFA via server-side challenge tokens (not client-supplied flags)
- Role-based access control: 5 roles, least-privilege permissions
- Strict multi-tenant isolation — every query scoped to your organization
On certifications: Complicer does not yet hold SOC 2 or ISO 27001 certification, and we will not claim either until it is formally awarded. We would rather tell you exactly what we do than badge a control we have not had independently audited. The hosting infrastructure beneath us (Fly.io) maintains its own compliance posture for the layers it operates.
Need a full procurement pack?
We can send the DPA review package (via [email protected]), the subprocessor list, and a security control summary as a single document for your vendor-onboarding review.
Request the procurement packMore on our security posture
See the broader security overview, or read how we keep AI honest in our testing methodology.