European by architecture, not by label.
CRCX runs on infrastructure it owns in Europe, auditable end to end, building toward owned servers in Germany. No US cloud provider. No sub processor outside the EU.
Sovereignty is what makes the proof acceptable.
For an organisation under NIS2, DORA, and GDPR, sovereignty is not a technical preference. It is what makes the proof acceptable to a party that will not accept a US hosted answer. Sophisticated European clients in regulated sectors will not let a US hosted platform collect their evidence, regardless of where the data sits. The design is sovereign today. The execution is progressive, and we say exactly where it stands.
- No US cloud provider
- No sub processor outside the EU
- EU hosted processing, end to end auditable
- Owned servers in Germany
The state of your access, not your opinion of it.
The identity risk data CRCX collects is automated, system generated, and tamper resistant. It reflects the current state of who and what can reach your critical systems, not what anyone believes is true about their access controls.
- A form somebody fills in
- True on the day it was signed
- Reflects a belief about the controls
- Repeated once a year
- Read straight from the source systems
- The current state, continuously
- Reflects what is actually configured
- Tamper resistant and automated
Every score, back to its source.
Every score is documented, versioned, and independently audited. An insurer, an auditor, or a regulator can trace any score back to its source evidence. The methodology version is always cited.
82
Identity risk
IAM.01
Multi factor on all human identities
Okta
Directory read, scope limited
2026-07-22
14:02 UTC
v0.9
Versioned and published
Separation by structure, not by promise.
The advisory function and the insurance marketplace function are kept structurally separate. The data pipeline is automated and tamper evident. Independent audits verify the integrity of both.
Advisory
Helping a client reach a defensible posture. Paid by the client.
Marketplace
Verified risk data offered to insurers. Building toward.
The data pipeline is automated and tamper evident. Independent audits verify the integrity of both functions.
Built for the questionnaire before it arrives.
All data is processed on EU hosted infrastructure with full GDPR compliance, immutable audit logs, and a governance framework that gives you granular control over what is stored and what is shared. Data is encrypted at rest with AES 256 and in transit with TLS 1.3. No exceptions.
- Encryption at rest
- AES 256
- Encryption in transit
- TLS 1.3
- Processing location
- EU hosted
- Audit logs
- Immutable
- GDPR
- Full compliance
- Data control
- Granular
Read the detail.
Talk to us for the methodology summary, the conflict of interest charter, and the security documentation.
