Hosted in the EU
Infrastructure runs on AWS in the Europe (Milan) region. Data does not leave the European Union in the course of normal operation.
A tool for regulatory compliance has to be exemplary about its own security. This page describes, plainly, where your data lives, how it is protected, who processes it on our behalf, and how you stay in control.
Infrastructure runs on AWS in the Europe (Milan) region. Data does not leave the European Union in the course of normal operation.
TLS in transit; database and backups encrypted at rest. Passwords are hashed with bcrypt; API keys and two-factor secrets are never stored in clear.
Every organisation’s data is strictly scoped to its own tenant. Access is authenticated, role-based, and recorded in a tamper-evident registry.
Role-based access (administrator, approver, evaluator, read-only), optional two-factor authentication and SSO (OIDC), session expiry and revocation.
Multi-tenant isolation: each request is scoped to its organisation; cross-tenant access is prevented at the data layer.
Automated database backups with point-in-time recovery; off-site, versioned, encrypted copies to guard against accidental or malicious loss.
Infrastructure and application monitoring with alerting on anomalies; a public, live status page.
The activity registry is hash-chained so that reordering or deletion is detectable — the compliance evidence you may have to hand to an authority stays trustworthy.
A strict content-security policy, auto-escaped templating, parameterised queries, and a CI gate (build, vet, race tests) that blocks a release that does not pass.
We use a small set of established providers to run the service. Each processes data only as needed to provide its function, under a data processing agreement.
| Provider | Purpose | Region |
|---|---|---|
| Cloud hosting, database, backups, transactional email (SES) and SMS alerts (End User Messaging) | EU (Milan · Frankfurt) | |
| CDN, DNS, DDoS protection and bot mitigation | Global / EU | |
| Subscription billing and payments | EU | |
| AI draft assistance (only text you submit to the assistant) | EU (Milan) | |
| Error monitoring and performance telemetry | EU (Frankfurt) | |
| Google Ireland Ltd. (Tag Manager · Analytics) | Website usage statistics (only with your consent) | EU (Ireland) · non-EEA transfers under standard contractual clauses |
The AI assistant is optional and processes only the text you explicitly submit to it; it never decides triage outcomes or deadlines. AI drafting runs on Amazon Bedrock in the EU (Milan) on Anthropic Claude models; the text you submit does not leave the European Union. We notify customers of material changes to this list.
We act as a data processor for the content you put into CRAnotify, and as controller for your account data. You can export your organisation’s data at any time and request erasure of personal data, subject to the evidence a regulation requires us to retain.
If you believe you have found a security issue in CRAnotify, write to us. We work with coordinated disclosure and reply within five business days.
No result for “”.
Try an article of the regulation (Art. 13, Art. 14), a product term (dossier, registry, SBOM), or write to support@cranotify.eu.