Skip to content
11 days until the Art. 14 reporting obligation (11 September 2026).
Documentation Support Risk class
01CRAnotify · Trust Center

How we protect your data

A tool for regulatory compliance has to be exemplary about its own security. This page describes, plainly, where your data lives, how it is protected, who processes it on our behalf, and how you stay in control.

01

Hosted in the EU

Infrastructure runs on AWS in the Europe (Milan) region. Data does not leave the European Union in the course of normal operation.

02

Encrypted

TLS in transit; database and backups encrypted at rest. Passwords are hashed with bcrypt; API keys and two-factor secrets are never stored in clear.

03

Isolated per organisation

Every organisation’s data is strictly scoped to its own tenant. Access is authenticated, role-based, and recorded in a tamper-evident registry.

Security practices

01

Access control

Role-based access (administrator, approver, evaluator, read-only), optional two-factor authentication and SSO (OIDC), session expiry and revocation.

02

Data segregation

Multi-tenant isolation: each request is scoped to its organisation; cross-tenant access is prevented at the data layer.

03

Backups & recovery

Automated database backups with point-in-time recovery; off-site, versioned, encrypted copies to guard against accidental or malicious loss.

04

Monitoring

Infrastructure and application monitoring with alerting on anomalies; a public, live status page.

05

Evidence integrity

The activity registry is hash-chained so that reordering or deletion is detectable — the compliance evidence you may have to hand to an authority stays trustworthy.

06

Secure development

A strict content-security policy, auto-escaped templating, parameterised queries, and a CI gate (build, vet, race tests) that blocks a release that does not pass.

Sub-processors

We use a small set of established providers to run the service. Each processes data only as needed to provide its function, under a data processing agreement.

ProviderPurposeRegion
Amazon Web ServicesCloud hosting, database, backups, transactional email (SES) and SMS alerts (End User Messaging)EU (Milan · Frankfurt)
CloudflareCDN, DNS, DDoS protection and bot mitigationGlobal / EU
StripeSubscription billing and paymentsEU
Amazon Bedrock (Anthropic Claude)AI draft assistance (only text you submit to the assistant)EU (Milan)
SentryError monitoring and performance telemetryEU (Frankfurt)
Google Ireland Ltd. (Tag Manager · Analytics)Website usage statistics (only with your consent)EU (Ireland) · non-EEA transfers under standard contractual clauses

The AI assistant is optional and processes only the text you explicitly submit to it; it never decides triage outcomes or deadlines. AI drafting runs on Amazon Bedrock in the EU (Milan) on Anthropic Claude models; the text you submit does not leave the European Union. We notify customers of material changes to this list.

Data protection & your rights

We act as a data processor for the content you put into CRAnotify, and as controller for your account data. You can export your organisation’s data at any time and request erasure of personal data, subject to the evidence a regulation requires us to retain.

Reporting a vulnerability

If you believe you have found a security issue in CRAnotify, write to us. We work with coordinated disclosure and reply within five business days.