craclock

Encryption

Narrative case fields (PEC rationale, free-text descriptions) are encrypted at rest with AES-GCM, under a per-org data key.

Audit chain

Every state change on a case — every field edit, every stage transition, every submission — appends to a hash-chained, append-only audit log. Every case exposes an endpoint to verify its own chain.

EU hosting

The hosted app runs in an EU region (Fly.io fra), with an EU-region Postgres, EU object storage, and nightly encrypted backups to a second EU provider.

Reporting a vulnerability

Email security@craclock.com. There’s no bug bounty yet, but every report is read, and responsible disclosure is credited.