Security for your CRA work
The core platform runs on our own infrastructure in Thayngen, Switzerland. Separate customer environments, protected data transmission, encrypted backups and local AI operated by codAIx form the foundation of our operations.
Hosting in Switzerland
The core platform runs on our own infrastructure in Thayngen. External services are used only for clearly identified functions; the related data flows are described in the Privacy Policy.
- Core systems operated in Thayngen
- Physical access restricted to authorised persons
Single-tenant environment
Each customer receives a logically and operationally separate environment. Test and production environments are also kept separate.
- Dedicated instance per customer
- Separate test and production environments
Encryption and access control
HTTPS/TLS protects data in transit; sensitive content and API keys are stored in encrypted form. Role-based permissions restrict access.
- Protected data transmission
- Role-based access permissions
Backups and recovery
Operationally required data is backed up daily in encrypted form. Restore tests are performed and documented.
- Daily encrypted backups
- Documented recovery test
AI and source code under your control
The default AI runs in Thayngen. Content is neither shared with external AI providers nor used for model training; cloud AI is enabled only when explicitly selected by the customer.
- Customer data is not used to train our own models
- Repository analysis only as an optional add-on feature
Controlled data flows
Vulnerability checks are performed server-side using only the required technical identifiers. The marketing website uses no analytics or advertising trackers.
- No transmission of the user IP address to vulnerability sources
- Details on external services in the privacy policy
Report a vulnerability
Have you discovered a possible vulnerability in crAIready? Security researchers and users can reach us via the contact form using the topic “Security”. Our security contact information is additionally published in machine-readable form in accordance with RFC 9116.
Further information
Supplementary details on the processing of personal data, on external services and on the contractual framework can be found in our legal documents.