Skip to main content
ComplicerAUDIT GRADE
MethodologyUse casesEU AI ActPricingBlogDocsSign inSTART FREE AUDIT
Procurement

Security, privacy & procurement

Everything your DPO, security, and procurement teams need to assess Complicer — in one place. Our Article 28 data processing terms, the complete subprocessor list, where your data lives, how long we keep it, and the controls that protect it. No certification we don't hold, no claim we can't back.

Data residency

EU — Frankfurt

Evidence retention

7 years

Subprocessors

9 named

DPA

Under counsel review

Data Processing Agreement (Art 28 GDPR)

When you run audits with Complicer, you are the data controller and Complicer acts as your data processor under Article 28 of the GDPR. Standard DPA under counsel review. Procurement review package available via [email protected]. An approved DPA will be executed before any customer processing begins.

  • Processing only on documented instructions from you, the controller
  • Confidentiality commitments for all personnel with access
  • Article 32 technical and organisational measures (see controls below)
  • Subprocessor transparency and prior-notice of changes (list below)
  • Assistance with data-subject requests, and breach notification without undue delay
  • Your choice of return or deletion of data at the end of the engagement
  • Transfers to US-based subprocessors (Anthropic, Stripe, Resend, Inngest, PostHog, Upstash, Sentry, and Cloudflare edge processing) — vendor agreements and transfer mechanisms, including Standard Contractual Clauses, are under counsel review; EU-region processing is our current operating posture
Request the review package

Enterprise plans include custom DPA terms — email [email protected].

Subprocessors

The third parties we rely on to deliver Complicer, what each one is used for, where your data is processed, and exactly what flows to them. We notify customers before adding or changing a subprocessor.

SubprocessorPurposeData locationWhat we share
Fly.ioApplication hosting, compute, and managed PostgreSQL database — our primary processorEuropean Union — Frankfurt, Germany (fra); data at rest in the EUAll application data: accounts, websites, audits, findings, and evidence. This is where your data lives.
CloudflareDNS, reverse proxy, WAF/DDoS protection (transit only), and R2 object storage for sealed evidenceEdge: global transit network. R2 evidence storage: EU jurisdiction (verified)Request metadata in transit (IP addresses, headers, URLs); sealed evidence bundles at rest in R2.
AnthropicAI classification of cookie purposes and AI-assisted remediation textUnited StatesCookie names and domains, tracker signals, policy-text excerpts. No customer-site visitor data by design, and no account credentials or payment data. The AI never makes the final compliance decision — deterministic guardrails override it.
StripeSubscription billing and payment processingUnited States (Stripe Inc.); EU entity available (Stripe Payments Europe Ltd, Ireland)Billing contact and subscription tier. Payment card data is handled entirely by Stripe — Complicer never sees or stores card numbers.
ResendTransactional email delivery (audit notifications, invites, scheduled summaries)United StatesUser names and email addresses; notification content (audit titles, site names). Scheduled summaries carry compliance scores and result summaries. No sealed evidence files.
InngestBackground-job orchestration — the event bus for the audit pipelineUnited StatesEvent payloads: organization/audit/user identifiers, audited website URLs, recipient email addresses on notification events. No evidence files and no credentials.
PostHogProduct analytics — feature usage and funnel measurementUnited StatesEvents keyed by user/organization identifiers, including audited website URLs, audit identifiers, risk/scan scores, and finding counts; marketing funnel events can include a lead’s email address. No session recording.
UpstashRedis-backed rate-limit counters (abuse protection on public and expensive endpoints)United StatesShort-lived rate-limit counters keyed by user/organization identifiers and client IP addresses, expiring within minutes. No audit content.
SentryError monitoring for the application and background jobsUnited StatesError telemetry: stack traces and request metadata (URLs, IP addresses, user identifiers where available). No evidence files.

Fly.io

Purpose
Application hosting, compute, and managed PostgreSQL database — our primary processor
Data location
European Union — Frankfurt, Germany (fra); data at rest in the EU
What we share
All application data: accounts, websites, audits, findings, and evidence. This is where your data lives.

Cloudflare

Purpose
DNS, reverse proxy, WAF/DDoS protection (transit only), and R2 object storage for sealed evidence
Data location
Edge: global transit network. R2 evidence storage: EU jurisdiction (verified)
What we share
Request metadata in transit (IP addresses, headers, URLs); sealed evidence bundles at rest in R2.

Anthropic

Purpose
AI classification of cookie purposes and AI-assisted remediation text
Data location
United States
What we share
Cookie names and domains, tracker signals, policy-text excerpts. No customer-site visitor data by design, and no account credentials or payment data. The AI never makes the final compliance decision — deterministic guardrails override it.

Stripe

Purpose
Subscription billing and payment processing
Data location
United States (Stripe Inc.); EU entity available (Stripe Payments Europe Ltd, Ireland)
What we share
Billing contact and subscription tier. Payment card data is handled entirely by Stripe — Complicer never sees or stores card numbers.

Resend

Purpose
Transactional email delivery (audit notifications, invites, scheduled summaries)
Data location
United States
What we share
User names and email addresses; notification content (audit titles, site names). Scheduled summaries carry compliance scores and result summaries. No sealed evidence files.

Inngest

Purpose
Background-job orchestration — the event bus for the audit pipeline
Data location
United States
What we share
Event payloads: organization/audit/user identifiers, audited website URLs, recipient email addresses on notification events. No evidence files and no credentials.

PostHog

Purpose
Product analytics — feature usage and funnel measurement
Data location
United States
What we share
Events keyed by user/organization identifiers, including audited website URLs, audit identifiers, risk/scan scores, and finding counts; marketing funnel events can include a lead’s email address. No session recording.

Upstash

Purpose
Redis-backed rate-limit counters (abuse protection on public and expensive endpoints)
Data location
United States
What we share
Short-lived rate-limit counters keyed by user/organization identifiers and client IP addresses, expiring within minutes. No audit content.

Sentry

Purpose
Error monitoring for the application and background jobs
Data location
United States
What we share
Error telemetry: stack traces and request metadata (URLs, IP addresses, user identifiers where available). No evidence files.

Your application data lives in the EU (Fly.io, Frankfurt). Some subprocessors involve US data flows — Anthropic for AI classification; Stripe, Resend, and Cloudflare for billing, email, and edge proxying; and Inngest, PostHog, Upstash, and Sentry for job orchestration, analytics, rate limiting, and error monitoring. Transfer mechanisms for these vendors, including Standard Contractual Clauses, are under counsel review — none is an executed record yet; EU-region processing is our current operating posture. The Anthropic transfer is limited to the signals needed for classification, and the AI never issues a final compliance verdict — read how our methodology keeps deterministic guardrails in control.

EU data residency

Complicer is EU-by-default. Your application data — accounts, websites, audits, findings, and evidence — is stored and processed on Fly.io in the Frankfurt region (fra), inside the European Union. Every organization carries a data-region setting that defaults to EU.

AI classification is performed by Anthropic in the United States — only the minimal signals needed (cookie names and domains, tracker and policy signals) are sent, never your credentials, billing data, or raw evidence files. Supporting services with US data flows — job orchestration, analytics, rate limiting, error monitoring, email, and billing — are named in the subprocessor list above, each with exactly what it receives. Hosting and DNS sit behind a Cloudflare proxy in front of Fly.

Retention & deletion

We keep data only as long as it serves your compliance evidence trail, then delete it.

Evidence retention

  • Evidence is immutable and retained for 7 years by default
  • Each artifact is SHA-256 checksummed and Ed25519-signed, with optional RFC 3161 trusted timestamping
  • Locked evidence is protected from deletion (WORM-style)
  • Retention supports the multi-year defensibility a regulator inquiry needs

Deletion timelines

  • Expired evidence is purged automatically by a scheduled cleanup job
  • Demo and trial data, idempotency keys, and MFA tokens are pruned on the same job
  • On account closure, we return or delete your data at the end of the engagement
  • Deletion requests are honoured subject to legal-hold and the DPA terms

Security controls

The Article 32 technical measures referenced in the DPA. Every item here maps to something that actually ships in the product.

Tamper-evident audit log

  • Every audit-relevant action is written to a hash-chained log
  • SHA-256 content hash linked to the previous entry (previousHash)
  • Chain written inside a Serializable transaction
  • verifyAuditLogChain() fails closed on any unchained entry

Immutable signed evidence

  • Ed25519 signatures on evidence manifests
  • SHA-256 checksums on every evidence artifact
  • Optional RFC 3161 trusted timestamps (e.g. FreeTSA) on manifests, with a local-timestamp fallback
  • WORM-style lock prevents deletion of locked evidence

Encryption

  • TLS in transit for all connections
  • Jira and integration credentials encrypted with AES-256-GCM at rest
  • API keys stored as SHA-256 hashes, compared in constant time
  • Webhook signatures verified (Stripe, inbound payloads)

Authentication & access

  • Email + bcrypt-hashed passwords, optional TOTP MFA
  • MFA via server-side challenge tokens (not client-supplied flags)
  • Role-based access control: 5 roles, least-privilege permissions
  • Strict multi-tenant isolation — every query scoped to your organization

On certifications: Complicer does not yet hold SOC 2 or ISO 27001 certification, and we will not claim either until it is formally awarded. We would rather tell you exactly what we do than badge a control we have not had independently audited. The hosting infrastructure beneath us (Fly.io) maintains its own compliance posture for the layers it operates.

Need a full procurement pack?

We can send the DPA review package (via [email protected]), the subprocessor list, and a security control summary as a single document for your vendor-onboarding review.

Request the procurement pack

More on our security posture

See the broader security overview, or read how we keep AI honest in our testing methodology.

Security overviewOur testing methodology
ComplicerAUDIT GRADE

We test whether Reject actually works on your site — and seal the evidence you can hand to a regulator.

GDPR-ALIGNED · SHA-256 · Ed25519 · EU-W1
PRODUCT
Free scanUse casesMethodologyEU AI ActPricingDocsBlog
COMPANY
ContactSecurityTrust
LEGAL
PrivacyTermsSubprocessorsComplaint
EVIDENCE CHAIN INTACT · SHA-256 · Ed25519 · RFC 3161-READY© 2026 COMPLICER