Encryption
Narrative case fields (PEC rationale, free-text descriptions) are encrypted at rest with AES-GCM, under a per-org data key.
Audit chain
Every state change on a case — every field edit, every stage transition, every submission — appends to a hash-chained, append-only audit log. Every case exposes an endpoint to verify its own chain.
EU hosting
The hosted app runs in an EU region (Fly.io fra), with an EU-region
Postgres, EU object storage, and nightly encrypted backups to a second EU
provider.
Reporting a vulnerability
Email security@craclock.com. There’s no bug bounty yet, but every report is read, and responsible disclosure is credited.