Security is in our DNA
As a compliance automation platform, we hold ourselves to the highest security standards. Your data protection is not just a feature — it's the foundation of everything we build.
Encryption
At rest + TLS 1.3
Data residency
EU (Frankfurt)
Scan canary
Every 6 hours
Evidence
SHA-256 + Ed25519
How we protect your data
A multi-layered approach to security across every level of the platform.
Encryption
Data is encrypted at rest and in transit.
- Encrypted at rest: database volumes (Fly.io) and evidence storage (Cloudflare R2, AES-256)
- TLS for all data in transit — complicer.com negotiates TLS 1.3
- Evidence artifacts additionally encrypted at the application layer
- Signing and encryption keys held as access-controlled platform secrets — never in code or images
Infrastructure
Application, database, and evidence storage run in the European Union.
- Application and PostgreSQL on Fly.io in Frankfurt, Germany (fra); evidence in Cloudflare R2 under EU jurisdiction
- Supporting services with US data flows are named — with exactly what each receives — on our procurement page
- Cloudflare network-level DDoS protection and WAF in front of the application
- Hosting provider (Fly.io) maintains its own compliance posture for the layers it operates
Access control
Granular access controls ensure only authorized users can access your data.
- Role-based access control (RBAC) for all accounts
- Multi-factor authentication (MFA) support
- SSO integration (Azure AD, Okta) for Enterprise
- Session management with automatic timeout
Compliance
We hold ourselves to the same compliance standards we help you achieve.
- GDPR-aligned data processing
- Tamper-evident evidence: SHA-256 hash-chained + Ed25519-signed
- No SOC 2 / ISO 27001 yet — we will not claim a control we have not been awarded
- Article 28 DPA drafted and in legal review — see our procurement page
Incident response
Automated failure detection with honest notification commitments.
- Synthetic scan canary every 6 hours, dead-letter alerting, and error monitoring
- Documented operational runbook and per-incident root-cause records
- Personal-data breach notification without undue delay (GDPR Art. 33)
- Root-cause review after every incident
Security testing
Recurring adversarial review of the codebase and its controls.
- Internal security sweeps across tenant isolation, authorization, and abuse paths — findings tracked to closure
- Independent cross-model adversarial reviews on security-relevant changes
- No accredited third-party penetration test yet — planned; we will not claim one until it has happened
Data backup
Snapshot-based recovery with honestly stated limits.
- Automated daily database volume snapshots with 5-day retention (Fly.io)
- Volumes encrypted; evidence stored separately in Cloudflare R2 (EU) with SHA-256 checksums
- Recovery is snapshot-based — recovery point up to 24 hours; we do not claim point-in-time recovery
Responsible disclosure
We welcome security researchers and maintain a responsible disclosure program.
- Dedicated security contact: [email protected]
- Prompt acknowledgment — typically within one business day
- Safe harbor for good-faith security research
- Credit to verified reporters on request
Need the full procurement picture?
Our procurement page carries the complete subprocessor list, EU residency detail, retention and deletion policy, and the Article 28 DPA review draft — in one place.
Security & procurementNo email required. Free to download.
Report a vulnerability
Found a security issue? We appreciate responsible disclosure. Please report vulnerabilities to our security team and we will respond within 24 hours.
[email protected]Security questions?
Have questions about our security practices or need our Data Processing Agreement? Our team is happy to help with any security-related inquiries.
Contact our security team