Skip to content

CRCX is in its founding stage. Continuous proof for identity risk is live today.

European by architecture, not by label.

CRCX runs on infrastructure it owns in Europe, auditable end to end, building toward owned servers in Germany. No US cloud provider. No sub processor outside the EU.

Sovereign infrastructure, by design

Sovereignty is what makes the proof acceptable.

For an organisation under NIS2, DORA, and GDPR, sovereignty is not a technical preference. It is what makes the proof acceptable to a party that will not accept a US hosted answer. Sophisticated European clients in regulated sectors will not let a US hosted platform collect their evidence, regardless of where the data sits. The design is sovereign today. The execution is progressive, and we say exactly where it stands.

Infrastructure postureFounding stage · 2026-07
  • No US cloud providerLive
  • No sub processor outside the EULive
  • EU hosted processing, end to end auditableLive
  • Owned servers in GermanyBuilding toward
Sovereign by design today · Execution stated exactly

Verified data, not self attestation

The state of your access, not your opinion of it.

The identity risk data CRCX collects is automated, system generated, and tamper resistant. It reflects the current state of who and what can reach your critical systems, not what anyone believes is true about their access controls.

Self attestation
  • A form somebody fills in
  • True on the day it was signed
  • Reflects a belief about the controls
  • Repeated once a year
System generated
  • Read straight from the source systems
  • The current state, continuously
  • Reflects what is actually configured
  • Tamper resistant and automated

A methodology you can trace

Every score, back to its source.

Every score is documented, versioned, and independently audited. An insurer, an auditor, or a regulator can trace any score back to its source evidence. The methodology version is always cited.

TraceabilityAny score · Back to source
  1. 01 · Score

    82

    Identity risk

  2. 02 · Control

    IAM.01

    Multi factor on all human identities

  3. 03 · Source

    Okta

    Directory read, scope limited

  4. 04 · Collected

    2026-07-22

    14:02 UTC

  5. 05 · Method

    v0.9

    Versioned and published

Every step recorded · Nothing self reported

Conflict of interest, managed by design

Separation by structure, not by promise.

The advisory function and the insurance marketplace function are kept structurally separate. The data pipeline is automated and tamper evident. Independent audits verify the integrity of both.

Function

Advisory

Helping a client reach a defensible posture. Paid by the client.

Function

Marketplace

Verified risk data offered to insurers. Building toward.

Structural separation

The data pipeline is automated and tamper evident. Independent audits verify the integrity of both functions.

Data governance you can hand to procurement

Built for the questionnaire before it arrives.

All data is processed on EU hosted infrastructure with full GDPR compliance, immutable audit logs, and a governance framework that gives you granular control over what is stored and what is shared. Data is encrypted at rest with AES 256 and in transit with TLS 1.3. No exceptions.

Data governancev0.9 · 2026-07
Encryption at rest
AES 256
Encryption in transit
TLS 1.3
Processing location
EU hosted
Audit logs
Immutable
GDPR
Full compliance
Data control
Granular
No exceptions

Read the detail.

Talk to us for the methodology summary, the conflict of interest charter, and the security documentation.