Trust & Security

Security for your CRA work

The core platform runs on our own infrastructure in Thayngen, Switzerland. Separate customer environments, protected data transmission, encrypted backups and local AI operated by codAIx form the foundation of our operations.

Hosting in Switzerland

The core platform and the systems operated by codAIx itself run on our own infrastructure in Thayngen. External services are used only for clearly designated functions; the respective data flows are described in the privacy policy.

  • Core systems operated in Thayngen
  • Physical access restricted to authorised persons

Single-tenant environment per customer

Each customer receives their own environment, separated logically and operationally. Customer data is not processed together with the data of other customers in a shared application instance. Test and production environments are separated from each other.

  • Dedicated instance per customer
  • Separate test and production environments

Encryption and access control

Connections to the platform are protected via HTTPS/TLS. Passwords are not stored in plain text. Role-based permissions limit access within the platform.

  • Protected data transmission
  • Role-based access permissions

Backups and recovery

Encrypted backups of the operationally required data are created daily. Restoration from the backups has been successfully tested and documented. Details of the internal backup concept are not disclosed publicly.

  • Daily encrypted backups
  • Documented recovery test

AI and source code under your control

By default, AI processing takes place on infrastructure operated by codAIx in Thayngen. No content is passed on to third-party AI model providers or used to train our own models. An optional cloud AI is used only after it has been explicitly activated. crAIready can also be used without AI and without uploading any source code.

  • Customer data is not used to train our own models
  • Repository analysis only as an optional add-on feature

Controlled data flows

Queries to vulnerability sources are performed server-side; the user's browser does not contact these services directly. Only the technical identifiers required for matching are transmitted. The marketing website does not use any analytics or advertising trackers.

  • No transmission of the user IP address to vulnerability sources
  • Details on external services in the privacy policy

Report a vulnerability

Have you discovered a possible vulnerability in crAIready? Security researchers and users can reach us via the contact form using the topic “Security”. Our security contact information is additionally published in machine-readable form in accordance with RFC 9116.

Further information

Supplementary details on the processing of personal data, on external services and on the contractual framework can be found in our legal documents.