Proof where we have it. Honestywhere we don't.
Security, data residency, subprocessors, and evidence integrity — everything your DPO needs to evaluate Complicer before you buy, including exactly what we don't hold yet.
Security practices
Application data is encrypted at rest — database volumes and evidence storage alike — and in transit over TLS 1.3. Every account can turn on multi-factor authentication, and every database query is scoped to your organization, with no cross-tenant access path. Signing and encryption keys are held as access-controlled platform secrets, never checked into code or images. The full control list is on our security page; the Article 28/32 mapping is on our procurement page.
FULL SECURITY CONTROLS →Data residency
Your application data — accounts, websites, audits, findings — is stored and processed on Fly.io in Frankfurt, Germany (region fra), inside the EU. Sealed evidence bundles are stored separately in Cloudflare R2 under EU jurisdiction. AI classification is one step that sends content abroad: Anthropic receives only the minimal signals needed for classification, never credentials, billing data, or raw evidence files, and never issues the final compliance verdict itself. 7 of our 9 named subprocessors have a US data flow — Anthropic among them — each listed with exactly what it receives.
Subprocessors
We rely on 9 named subprocessors to run Complicer, from application hosting to AI classification to error monitoring. Each one is listed with its purpose, data location, and exactly what flows to it, last reviewed 18 July 2026. We notify customers before adding or changing a subprocessor.
FULL SUBPROCESSOR REGISTER →Data processing agreement
Standard DPA under counsel review. Procurement review package available via [email protected]. An approved DPA will be executed before any customer processing begins.
Evidence integrity
Complicer does not hold SOC 2 or ISO 27001 certification. We will not claim either until it is formally awarded — we would rather tell you exactly what we do than badge a control nobody has independently audited.
Instead, every audit is sealed as evidence you can check yourself. Each artifact is hashed with SHA-256 at capture time, so any later change to a single byte breaks the hash. The manifest is signed with an Ed25519 key, binding it to Complicer. Our timestamping is RFC 3161-ready: when a Time-Stamping Authority is configured, it countersigns the bundle; otherwise the bundle carries a local timestamp, and the report states which was used — we never claim active third-party timestamping we haven't turned on. Separately, every audit-log entry chains to the one before it by hash, so a tampered or deleted entry breaks the chain. Every regulator export ships with an offline verifier script — plain Node.js, no dependency on our servers — so your DPO, or a regulator, can re-check the evidence independently.
Uptime & status
We don't yet publish a public uptime history. Operational monitoring includes a synthetic audit canary that runs end-to-end audits against a live site multiple times a day, with alerting the moment one stops completing.
Need the full procurement picture?
Our security & procurement page adds retention and deletion policy, plus the full security control list, in one place.
SECURITY & PROCUREMENT →Questions for your DPO or security team?
We are happy to walk through this page, the subprocessor list, or the DPA status directly.
[email protected] →