Security, privacy & procurement
Everything your DPO, security, and procurement teams need to assess Complicer — in one place. Our Article 28 data processing terms, the complete subprocessor list, where your data lives, how long we keep it, and the controls that protect it. No certification we don't hold, no claim we can't back.
Data residency
EU — Frankfurt
Evidence retention
7 years
Subprocessors
10 named
DPA
Draft in legal review
Data Processing Agreement (Art 28 GDPR)
When you run audits with Complicer, you are the data controller and Complicer acts as your data processor under Article 28 of the GDPR. Our Article 28 Data Processing Agreement is in final legal review and is available to procurement teams on request before purchase.
- Processing only on documented instructions from you, the controller
- Confidentiality commitments for all personnel with access
- Article 32 technical and organisational measures (see controls below)
- Subprocessor transparency and prior-notice of changes (list below)
- Assistance with data-subject requests, and breach notification without undue delay
- Your choice of return or deletion of data at the end of the engagement
- Transfers to US-based subprocessors (Anthropic, Stripe, Resend, Inngest, PostHog, Upstash, Sentry, and Cloudflare edge processing) under EU Standard Contractual Clauses in each vendor's data-processing terms
The draft is shared for procurement review only and is not yet offered for signature. Enterprise plans include custom DPA terms — email [email protected].
Subprocessors
The third parties we rely on to deliver Complicer, what each one is used for, where your data is processed, and exactly what flows to them. We notify customers before adding or changing a subprocessor.
| Subprocessor | Purpose | Data location | What we share |
|---|---|---|---|
| Fly.io | Application hosting, compute, and managed PostgreSQL database | European Union — Frankfurt, Germany (fra) | All application data: accounts, websites, audits, findings, evidence. This is our primary processor — your data lives here. |
| Cloudflare | Reverse proxy, DNS, TLS termination, and edge caching; R2 object storage (EU jurisdiction) for evidence artifacts | Edge: global network (EU prioritised). Evidence storage: R2, EU jurisdiction | Request metadata in transit (IP address, request headers, URLs) for proxying and DDoS/WAF protection, plus sealed evidence bundles stored at rest in Cloudflare R2 under EU jurisdiction. |
| Anthropic (Claude) | AI classification of findings and AI-assisted remediation suggestions | United States | Audit-derived signals needed for classification (e.g. page text snippets, cookie names, finding context). No account credentials and no payment data are sent. AI never makes a final compliance decision — deterministic guardrails override it. See our methodology. |
| Resend | Transactional email delivery (audit notifications, invites, alerts, scheduled summaries) | United States / EU | Recipient email address and the contents of the notification (e.g. audit completed, trial ending). Scheduled summaries (weekly digest, monthly board report) contain compliance scores and result summaries. No sealed evidence files. |
| Stripe | Subscription billing and payment processing | United States / EU | Billing contact, subscription tier, and payment details. Payment card data is handled entirely by Stripe — Complicer never sees or stores card numbers. |
| Inngest | Background-job orchestration (audit pipeline queue, scheduled jobs, alerting) | United States | Job event payloads: organization/audit/user identifiers, audited website URLs, and recipient email addresses on notification jobs. No evidence files and no credentials. |
| PostHog | Product analytics (feature usage, funnel measurement) | United States | Usage events keyed by user/organization identifiers, including audited website URLs, audit identifiers, scores, and finding counts; marketing funnel events can include a lead's email address. No session recording, no evidence files. |
| Upstash | Redis-backed rate limiting (abuse protection on public and expensive endpoints) | United States (US-based vendor; transient data only) | Short-lived rate-limit counters keyed by user/organization identifiers and client IP addresses, expiring within minutes. No audit content. |
| Sentry | Error monitoring for the application and background jobs | United States | Error telemetry: stack traces and request metadata (URLs, IP addresses, user identifiers where available). No evidence files. |
| FreeTSA | RFC 3161 trusted timestamping of evidence manifests — not currently enabled | European Union (Germany) | Not active in production today: evidence manifests currently carry an honest local timestamp instead. When enabled, only a SHA-256 hash of the manifest is sent — never the underlying audit content. |
Fly.io
- Purpose
- Application hosting, compute, and managed PostgreSQL database
- Data location
- European Union — Frankfurt, Germany (fra)
- What we share
- All application data: accounts, websites, audits, findings, evidence. This is our primary processor — your data lives here.
Cloudflare
- Purpose
- Reverse proxy, DNS, TLS termination, and edge caching; R2 object storage (EU jurisdiction) for evidence artifacts
- Data location
- Edge: global network (EU prioritised). Evidence storage: R2, EU jurisdiction
- What we share
- Request metadata in transit (IP address, request headers, URLs) for proxying and DDoS/WAF protection, plus sealed evidence bundles stored at rest in Cloudflare R2 under EU jurisdiction.
Anthropic (Claude)
- Purpose
- AI classification of findings and AI-assisted remediation suggestions
- Data location
- United States
- What we share
- Audit-derived signals needed for classification (e.g. page text snippets, cookie names, finding context). No account credentials and no payment data are sent. AI never makes a final compliance decision — deterministic guardrails override it. See our methodology.
Resend
- Purpose
- Transactional email delivery (audit notifications, invites, alerts, scheduled summaries)
- Data location
- United States / EU
- What we share
- Recipient email address and the contents of the notification (e.g. audit completed, trial ending). Scheduled summaries (weekly digest, monthly board report) contain compliance scores and result summaries. No sealed evidence files.
Stripe
- Purpose
- Subscription billing and payment processing
- Data location
- United States / EU
- What we share
- Billing contact, subscription tier, and payment details. Payment card data is handled entirely by Stripe — Complicer never sees or stores card numbers.
Inngest
- Purpose
- Background-job orchestration (audit pipeline queue, scheduled jobs, alerting)
- Data location
- United States
- What we share
- Job event payloads: organization/audit/user identifiers, audited website URLs, and recipient email addresses on notification jobs. No evidence files and no credentials.
PostHog
- Purpose
- Product analytics (feature usage, funnel measurement)
- Data location
- United States
- What we share
- Usage events keyed by user/organization identifiers, including audited website URLs, audit identifiers, scores, and finding counts; marketing funnel events can include a lead's email address. No session recording, no evidence files.
Upstash
- Purpose
- Redis-backed rate limiting (abuse protection on public and expensive endpoints)
- Data location
- United States (US-based vendor; transient data only)
- What we share
- Short-lived rate-limit counters keyed by user/organization identifiers and client IP addresses, expiring within minutes. No audit content.
Sentry
- Purpose
- Error monitoring for the application and background jobs
- Data location
- United States
- What we share
- Error telemetry: stack traces and request metadata (URLs, IP addresses, user identifiers where available). No evidence files.
FreeTSA
- Purpose
- RFC 3161 trusted timestamping of evidence manifests — not currently enabled
- Data location
- European Union (Germany)
- What we share
- Not active in production today: evidence manifests currently carry an honest local timestamp instead. When enabled, only a SHA-256 hash of the manifest is sent — never the underlying audit content.
Your application data lives in the EU (Fly.io, Frankfurt). Some subprocessors involve US data flows — Anthropic for AI classification; Stripe, Resend, and Cloudflare for billing, email, and edge proxying; and Inngest, PostHog, Upstash, and Sentry for job orchestration, analytics, rate limiting, and error monitoring — each covered by EU Standard Contractual Clauses. The Anthropic transfer is limited to the signals needed for classification, and the AI never issues a final compliance verdict — read how our methodology keeps deterministic guardrails in control.
EU data residency
Complicer is EU-by-default. Your application data — accounts, websites, audits, findings, and evidence — is stored and processed on Fly.io in the Frankfurt region (fra), inside the European Union. Every organization carries a data-region setting that defaults to EU.
AI classification is performed by Anthropic in the United States — only the minimal signals needed (cookie names and domains, tracker and policy signals) are sent, never your credentials, billing data, or raw evidence files. Supporting services with US data flows — job orchestration, analytics, rate limiting, error monitoring, email, and billing — are named in the subprocessor list above, each with exactly what it receives. Hosting and DNS sit behind a Cloudflare proxy in front of Fly.
Retention & deletion
We keep data only as long as it serves your compliance evidence trail, then delete it.
Evidence retention
- Evidence is immutable and retained for 7 years by default
- Each artifact is SHA-256 checksummed and Ed25519-signed, with optional RFC 3161 trusted timestamping
- Locked evidence is protected from deletion (WORM-style)
- Retention supports the multi-year defensibility a regulator inquiry needs
Deletion timelines
- Expired evidence is purged automatically by a scheduled cleanup job
- Demo and trial data, idempotency keys, and MFA tokens are pruned on the same job
- On account closure, we return or delete your data at the end of the engagement
- Deletion requests are honoured subject to legal-hold and the DPA terms
Security controls
The Article 32 technical measures referenced in the DPA. Every item here maps to something that actually ships in the product.
Tamper-evident audit log
- Every audit-relevant action is written to a hash-chained log
- SHA-256 content hash linked to the previous entry (previousHash)
- Chain written inside a Serializable transaction
- verifyAuditLogChain() fails closed on any unchained entry
Immutable signed evidence
- Ed25519 signatures on evidence manifests
- SHA-256 checksums on every evidence artifact
- Optional RFC 3161 trusted timestamps (e.g. FreeTSA) on manifests, with a local-timestamp fallback
- WORM-style lock prevents deletion of locked evidence
Encryption
- TLS in transit for all connections
- Jira and integration credentials encrypted with AES-256-GCM at rest
- API keys stored as SHA-256 hashes, compared in constant time
- Webhook signatures verified (Stripe, inbound payloads)
Authentication & access
- Email + bcrypt-hashed passwords, optional TOTP MFA
- MFA via server-side challenge tokens (not client-supplied flags)
- Role-based access control: 5 roles, least-privilege permissions
- Strict multi-tenant isolation — every query scoped to your organization
On certifications: Complicer does not yet hold SOC 2 or ISO 27001 certification, and we will not claim either until it is formally awarded. We would rather tell you exactly what we do than badge a control we have not had independently audited. The hosting infrastructure beneath us (Fly.io) maintains its own compliance posture for the layers it operates.
Need a full procurement pack?
We can send the DPA, subprocessor list, and a security control summary as a single document for your vendor-onboarding review.
Request the procurement packMore on our security posture
See the broader security overview, or read how we keep AI honest in our testing methodology.