Data Security

How we protect your data: encryption, access controls, vulnerability disclosure, and incident response.

Security at CRA Evidence

CRA Evidence is hosted on AWS in the European Union. All customer data is encrypted in transit and at rest. We use tenant isolation controls to keep each organisation's data separated from other customers.

Infrastructure

  • Cloud: Hosted in the European Union (Dublin, Ireland)
  • Data Residency: All customer data is stored in the EU. Limited international transfers (for example, payment processing via Stripe in the US) are covered by Standard Contractual Clauses / EU-US Data Privacy Framework; see our subprocessor list
  • Network: Production services are deployed in a restricted network architecture
  • Audit: Security-relevant user and system actions are recorded in an append-only audit trail

Encryption

  • In Transit: TLS 1.2 or higher on all connections (HTTPS enforced)
  • At Rest: AES-256 encryption on all data stores
  • Key Management: Dedicated key management service; keys are never exposed to the application layer
  • Credentials: Passwords hashed with memory-hard algorithms; API keys hashed before storage (plaintext never retained)

Authentication & Access Control

  • Login: Email/password, OAuth (Google, Microsoft, GitHub), SAML SSO
  • MFA: TOTP-based multi-factor authentication with backup codes; organisations can enforce MFA for all members
  • Roles: Four roles per organisation (Owner, Admin, Member, Viewer), following the principle of least privilege
  • API Keys: Scoped permissions, individually revocable
  • SSO Enforcement: Organisations can require SAML SSO for all members

Tenant Isolation

CRA Evidence is a multi-tenant platform designed to keep each customer's workspace, evidence, products, SBOMs, vulnerabilities, and compliance documents logically isolated from other customers.

  • Customer workspaces are separated by access controls and application-level authorization checks
  • Product security and compliance records are scoped to the owning organisation
  • File storage and audit records are separated by customer workspace
  • Access to customer data is logged for accountability and investigation

Vulnerability Management

  • Vulnerability Knowledge Base: Multi-source vulnerability intelligence is refreshed regularly from authoritative public sources and used as an independent verification layer.
  • Dependency Monitoring: Automated checks on application dependencies
  • Patch Management: Regular updates to application and infrastructure components

Data Retention

  • Active account data: Retained while subscription is active
  • Deleted accounts: Data removed within 30 days of request
  • Audit logs: 10-year retention policy
  • Backups: Encrypted daily automated snapshots

GDPR & Privacy

  • Data Processing Agreement (DPA): Available on request (privacy@craevidence.com)
  • Records of Processing Activities (ROPA): Maintained per GDPR Article 30
  • Subprocessors: Published list with 30-day change notification
  • Data Portability: SBOM export in standard formats (CycloneDX, SPDX)
  • Data Deletion: Account and all associated data deleted within 30 days of request
  • Privacy Policy: Read our privacy policy

Compliance

Our Compliance

  • Compliant with GDPR (EU 2016/679): ROPA, DPA, subprocessor list, privacy policy
  • EU data residency: all data hosted in the European Union
  • RFC 9116: security.txt published
  • ISO 29147/30111 aligned: Coordinated Vulnerability Disclosure process

Infrastructure Provider Certifications

Our infrastructure provider maintains SOC 1/2/3, ISO 27001, ISO 27017, ISO 27018, and C5 (German BSI) certifications for the EU region we operate in.

Roadmap

  • Independent penetration testing (planned)
  • SOC 2 Type II (planned)
  • ISO 27001 (under evaluation)

We are building our compliance posture alongside our product. This page reflects where we are today.

Vulnerability Disclosure

We welcome responsible security research. If you discover a vulnerability in our platform, please report it.

How to Report

  • Email: security@craevidence.com
  • Response: Acknowledged within 3 business days (typically much faster), triage decision within 10 business days

Scope

  • In scope: *.craevidence.com, the CRA Evidence API, the CRA Evidence CLI
  • Out of scope: Third-party services, social engineering, denial-of-service attacks

Safe Harbor

We will not pursue legal action against security researchers who:

  • Act in good faith
  • Avoid privacy violations, data destruction, or service disruption
  • Report findings promptly and allow reasonable time for remediation

CVD Policy

We follow ISO 29147/30111 standards for Coordinated Vulnerability Disclosure.

Contact

Last updated: June 2026.

Security Contact
Security Team
security@craevidence.com
General Inquiries
Contact Form
Compliance

Our Compliance

  • Compliant with GDPR (EU 2016/679)
  • EU data residency
  • RFC 9116 (security.txt)
  • ISO 29147/30111 aligned (CVD)

Infrastructure Provider

SOC 1/2/3, ISO 27001, ISO 27017, ISO 27018, C5

Roadmap

  • Independent penetration testing
  • SOC 2 Type II
  • ISO 27001

Questions About Our Security Practices?

We're committed to transparency. Reach out if you have any security-related questions.