Trust & Security

Security for your CRA work

The core platform runs on our own infrastructure in Thayngen, Switzerland. Separate customer environments, protected data transmission, encrypted backups and local AI operated by codAIx form the foundation of our operations.

Hosting in Switzerland

The core platform runs on our own infrastructure in Thayngen. External services are used only for clearly identified functions; the related data flows are described in the Privacy Policy.

  • Core systems operated in Thayngen
  • Physical access restricted to authorised persons

Single-tenant environment

Each customer receives a logically and operationally separate environment. Test and production environments are also kept separate.

  • Dedicated instance per customer
  • Separate test and production environments

Encryption and access control

HTTPS/TLS protects data in transit; sensitive content and API keys are stored in encrypted form. Role-based permissions restrict access.

  • Protected data transmission
  • Role-based access permissions

Backups and recovery

Operationally required data is backed up daily in encrypted form. Restore tests are performed and documented.

  • Daily encrypted backups
  • Documented recovery test

AI and source code under your control

The default AI runs in Thayngen. Content is neither shared with external AI providers nor used for model training; cloud AI is enabled only when explicitly selected by the customer.

  • Customer data is not used to train our own models
  • Repository analysis only as an optional add-on feature

Controlled data flows

Vulnerability checks are performed server-side using only the required technical identifiers. The marketing website uses no analytics or advertising trackers.

  • No transmission of the user IP address to vulnerability sources
  • Details on external services in the privacy policy

Report a vulnerability

Have you discovered a possible vulnerability in crAIready? Security researchers and users can reach us via the contact form using the topic “Security”. Our security contact information is additionally published in machine-readable form in accordance with RFC 9116.

Further information

Supplementary details on the processing of personal data, on external services and on the contractual framework can be found in our legal documents.