Skip to main content
ComplicerAUDIT GRADE
MethodologyUse casesEU AI ActPricingBlogDocsSign inSTART FREE AUDIT
Procurement

Security, privacy & procurement

Everything your DPO, security, and procurement teams need to assess Complicer — in one place. Our Article 28 data processing terms, the complete subprocessor list, where your data lives, how long we keep it, and the controls that protect it. No certification we don't hold, no claim we can't back.

Data residency

EU — Frankfurt

Evidence retention

7 years

Subprocessors

10 named

DPA

Draft in legal review

Data Processing Agreement (Art 28 GDPR)

When you run audits with Complicer, you are the data controller and Complicer acts as your data processor under Article 28 of the GDPR. Our Article 28 Data Processing Agreement is in final legal review and is available to procurement teams on request before purchase.

  • Processing only on documented instructions from you, the controller
  • Confidentiality commitments for all personnel with access
  • Article 32 technical and organisational measures (see controls below)
  • Subprocessor transparency and prior-notice of changes (list below)
  • Assistance with data-subject requests, and breach notification without undue delay
  • Your choice of return or deletion of data at the end of the engagement
  • Transfers to US-based subprocessors (Anthropic, Stripe, Resend, Inngest, PostHog, Upstash, Sentry, and Cloudflare edge processing) under EU Standard Contractual Clauses in each vendor's data-processing terms
Request the review draft

The draft is shared for procurement review only and is not yet offered for signature. Enterprise plans include custom DPA terms — email [email protected].

Subprocessors

The third parties we rely on to deliver Complicer, what each one is used for, where your data is processed, and exactly what flows to them. We notify customers before adding or changing a subprocessor.

SubprocessorPurposeData locationWhat we share
Fly.ioApplication hosting, compute, and managed PostgreSQL databaseEuropean Union — Frankfurt, Germany (fra)All application data: accounts, websites, audits, findings, evidence. This is our primary processor — your data lives here.
CloudflareReverse proxy, DNS, TLS termination, and edge caching; R2 object storage (EU jurisdiction) for evidence artifactsEdge: global network (EU prioritised). Evidence storage: R2, EU jurisdictionRequest metadata in transit (IP address, request headers, URLs) for proxying and DDoS/WAF protection, plus sealed evidence bundles stored at rest in Cloudflare R2 under EU jurisdiction.
Anthropic (Claude)AI classification of findings and AI-assisted remediation suggestionsUnited StatesAudit-derived signals needed for classification (e.g. page text snippets, cookie names, finding context). No account credentials and no payment data are sent. AI never makes a final compliance decision — deterministic guardrails override it. See our methodology.
ResendTransactional email delivery (audit notifications, invites, alerts, scheduled summaries)United States / EURecipient email address and the contents of the notification (e.g. audit completed, trial ending). Scheduled summaries (weekly digest, monthly board report) contain compliance scores and result summaries. No sealed evidence files.
StripeSubscription billing and payment processingUnited States / EUBilling contact, subscription tier, and payment details. Payment card data is handled entirely by Stripe — Complicer never sees or stores card numbers.
InngestBackground-job orchestration (audit pipeline queue, scheduled jobs, alerting)United StatesJob event payloads: organization/audit/user identifiers, audited website URLs, and recipient email addresses on notification jobs. No evidence files and no credentials.
PostHogProduct analytics (feature usage, funnel measurement)United StatesUsage events keyed by user/organization identifiers, including audited website URLs, audit identifiers, scores, and finding counts; marketing funnel events can include a lead's email address. No session recording, no evidence files.
UpstashRedis-backed rate limiting (abuse protection on public and expensive endpoints)United States (US-based vendor; transient data only)Short-lived rate-limit counters keyed by user/organization identifiers and client IP addresses, expiring within minutes. No audit content.
SentryError monitoring for the application and background jobsUnited StatesError telemetry: stack traces and request metadata (URLs, IP addresses, user identifiers where available). No evidence files.
FreeTSARFC 3161 trusted timestamping of evidence manifests — not currently enabledEuropean Union (Germany)Not active in production today: evidence manifests currently carry an honest local timestamp instead. When enabled, only a SHA-256 hash of the manifest is sent — never the underlying audit content.

Fly.io

Purpose
Application hosting, compute, and managed PostgreSQL database
Data location
European Union — Frankfurt, Germany (fra)
What we share
All application data: accounts, websites, audits, findings, evidence. This is our primary processor — your data lives here.

Cloudflare

Purpose
Reverse proxy, DNS, TLS termination, and edge caching; R2 object storage (EU jurisdiction) for evidence artifacts
Data location
Edge: global network (EU prioritised). Evidence storage: R2, EU jurisdiction
What we share
Request metadata in transit (IP address, request headers, URLs) for proxying and DDoS/WAF protection, plus sealed evidence bundles stored at rest in Cloudflare R2 under EU jurisdiction.

Anthropic (Claude)

Purpose
AI classification of findings and AI-assisted remediation suggestions
Data location
United States
What we share
Audit-derived signals needed for classification (e.g. page text snippets, cookie names, finding context). No account credentials and no payment data are sent. AI never makes a final compliance decision — deterministic guardrails override it. See our methodology.

Resend

Purpose
Transactional email delivery (audit notifications, invites, alerts, scheduled summaries)
Data location
United States / EU
What we share
Recipient email address and the contents of the notification (e.g. audit completed, trial ending). Scheduled summaries (weekly digest, monthly board report) contain compliance scores and result summaries. No sealed evidence files.

Stripe

Purpose
Subscription billing and payment processing
Data location
United States / EU
What we share
Billing contact, subscription tier, and payment details. Payment card data is handled entirely by Stripe — Complicer never sees or stores card numbers.

Inngest

Purpose
Background-job orchestration (audit pipeline queue, scheduled jobs, alerting)
Data location
United States
What we share
Job event payloads: organization/audit/user identifiers, audited website URLs, and recipient email addresses on notification jobs. No evidence files and no credentials.

PostHog

Purpose
Product analytics (feature usage, funnel measurement)
Data location
United States
What we share
Usage events keyed by user/organization identifiers, including audited website URLs, audit identifiers, scores, and finding counts; marketing funnel events can include a lead's email address. No session recording, no evidence files.

Upstash

Purpose
Redis-backed rate limiting (abuse protection on public and expensive endpoints)
Data location
United States (US-based vendor; transient data only)
What we share
Short-lived rate-limit counters keyed by user/organization identifiers and client IP addresses, expiring within minutes. No audit content.

Sentry

Purpose
Error monitoring for the application and background jobs
Data location
United States
What we share
Error telemetry: stack traces and request metadata (URLs, IP addresses, user identifiers where available). No evidence files.

FreeTSA

Purpose
RFC 3161 trusted timestamping of evidence manifests — not currently enabled
Data location
European Union (Germany)
What we share
Not active in production today: evidence manifests currently carry an honest local timestamp instead. When enabled, only a SHA-256 hash of the manifest is sent — never the underlying audit content.

Your application data lives in the EU (Fly.io, Frankfurt). Some subprocessors involve US data flows — Anthropic for AI classification; Stripe, Resend, and Cloudflare for billing, email, and edge proxying; and Inngest, PostHog, Upstash, and Sentry for job orchestration, analytics, rate limiting, and error monitoring — each covered by EU Standard Contractual Clauses. The Anthropic transfer is limited to the signals needed for classification, and the AI never issues a final compliance verdict — read how our methodology keeps deterministic guardrails in control.

EU data residency

Complicer is EU-by-default. Your application data — accounts, websites, audits, findings, and evidence — is stored and processed on Fly.io in the Frankfurt region (fra), inside the European Union. Every organization carries a data-region setting that defaults to EU.

AI classification is performed by Anthropic in the United States — only the minimal signals needed (cookie names and domains, tracker and policy signals) are sent, never your credentials, billing data, or raw evidence files. Supporting services with US data flows — job orchestration, analytics, rate limiting, error monitoring, email, and billing — are named in the subprocessor list above, each with exactly what it receives. Hosting and DNS sit behind a Cloudflare proxy in front of Fly.

Retention & deletion

We keep data only as long as it serves your compliance evidence trail, then delete it.

Evidence retention

  • Evidence is immutable and retained for 7 years by default
  • Each artifact is SHA-256 checksummed and Ed25519-signed, with optional RFC 3161 trusted timestamping
  • Locked evidence is protected from deletion (WORM-style)
  • Retention supports the multi-year defensibility a regulator inquiry needs

Deletion timelines

  • Expired evidence is purged automatically by a scheduled cleanup job
  • Demo and trial data, idempotency keys, and MFA tokens are pruned on the same job
  • On account closure, we return or delete your data at the end of the engagement
  • Deletion requests are honoured subject to legal-hold and the DPA terms

Security controls

The Article 32 technical measures referenced in the DPA. Every item here maps to something that actually ships in the product.

Tamper-evident audit log

  • Every audit-relevant action is written to a hash-chained log
  • SHA-256 content hash linked to the previous entry (previousHash)
  • Chain written inside a Serializable transaction
  • verifyAuditLogChain() fails closed on any unchained entry

Immutable signed evidence

  • Ed25519 signatures on evidence manifests
  • SHA-256 checksums on every evidence artifact
  • Optional RFC 3161 trusted timestamps (e.g. FreeTSA) on manifests, with a local-timestamp fallback
  • WORM-style lock prevents deletion of locked evidence

Encryption

  • TLS in transit for all connections
  • Jira and integration credentials encrypted with AES-256-GCM at rest
  • API keys stored as SHA-256 hashes, compared in constant time
  • Webhook signatures verified (Stripe, inbound payloads)

Authentication & access

  • Email + bcrypt-hashed passwords, optional TOTP MFA
  • MFA via server-side challenge tokens (not client-supplied flags)
  • Role-based access control: 5 roles, least-privilege permissions
  • Strict multi-tenant isolation — every query scoped to your organization

On certifications: Complicer does not yet hold SOC 2 or ISO 27001 certification, and we will not claim either until it is formally awarded. We would rather tell you exactly what we do than badge a control we have not had independently audited. The hosting infrastructure beneath us (Fly.io) maintains its own compliance posture for the layers it operates.

Need a full procurement pack?

We can send the DPA, subprocessor list, and a security control summary as a single document for your vendor-onboarding review.

Request the procurement pack

More on our security posture

See the broader security overview, or read how we keep AI honest in our testing methodology.

Security overviewOur testing methodology
ComplicerAUDIT GRADE

Outcome-driven GDPR compliance — banners that actually work, evidence you can show your auditor.

GDPR-ALIGNED · SHA-256 · Ed25519 · EU-W1
PRODUCT
Free scanUse casesMethodologyEU AI ActPricingDocsBlog
COMPANY
ContactSecurity
LEGAL
PrivacyTermsComplaint
EVIDENCE CHAIN INTACT · SHA-256 · Ed25519 · RFC 3161-READY© 2026 COMPLICER