Trust: the facts, and only the facts
What procurement, legal and security teams ask before signing. Verifiable facts only, including what we don't have yet.
Who publishes ResiPlan
- Publisher
- Cryptaguard BV
- Legal form
- Private limited company (BV) under Belgian law
- Company number (CBE)
- 1007.610.660
- Registered office
- Fazantenlaan 9, 1600 Sint-Pieters-Leeuw, Belgium
- Product
- ResiPlan
- Contact
- Contact form
Where your data lives, and who processes it
Business data is stored in the European Union. Sub-processors outside the EU are listed below with the safeguards that apply.
Convex
Database, serverless functions, real-time sync and file storage
OVHcloud
Application hosting (web server of the Service)
| Sub-processor | Scope | Purpose | Data location | Transfer safeguards |
|---|---|---|---|---|
Convex Convex, Inc. | Core service | Database, serverless functions, real-time sync and file storage | European Union — AWS eu-west-1 (Ireland), dedicated EU deployment | Data hosted in the EU; US support access covered by SCCs (2021/914) |
OVHcloud OVH SAS | Core service | Application hosting (web server of the Service) | European Union — France | No transfer outside the EU |
Resend Resend, Inc. | Core service | Transactional email delivery (invitations, notifications, alerts) | United States | SCCs (2021/914) |
Stripe Stripe Payments Europe, Ltd. | Billing (own processing) | Subscription payments and billing | European Union, with intra-group transfers to Stripe, Inc. (United States) | SCCs (2021/914) and, where applicable, an active DPF certification |
Anthropic Anthropic, PBC | AI (default) | Default AI provider (assistant, plan generation, analyses) — no training on customer data | United States | SCCs (2021/914) and, where applicable, an active DPF certification; per-organization "EU-only AI" option available |
OpenAI OpenAI, L.L.C. | AI (default) | Selected AI features and optional cloud transcription of crisis sessions (local alternative available) | United States | SCCs (2021/914) and, where applicable, an active DPF certification; per-organization "EU-only AI" option available |
Mistral AI Mistral AI | AI (EU option) | "EU-only AI" option: substitute AI provider configurable per organization | European Union — France | No transfer outside the EU |
Plausible Analytics Plausible Insights OÜ | Core service | Aggregate, cookieless audience measurement (website and application) | European Union | No transfer outside the EU |
Google Analytics 4 Google Ireland Limited | Core service | Detailed audience measurement of the website and application (journeys, traffic sources) — consent-gated | European Union and United States (Google infrastructure) | SCCs (2021/914) and, where applicable, an active DPF certification |
Microsoft Clarity Microsoft Ireland Operations Ltd. | Marketing site | Heatmaps and anonymized session replay on the marketing site — consent-gated | European Union, with possible intra-group transfers to Microsoft Corporation (United States) | SCCs (2021/914) and, where applicable, an active DPF certification |
Any new or replaced sub-processor is notified at least 30 days in advance (DPA, section 5.4.2).
Backups and recovery
- Full, encrypted export of the database every night (AES-256), files included.
- Retention: 14 daily and 8 weekly backups.
- Automated restore check every week: decryption, checksum, archive integrity and table census.
- Recovery point objective (RPO): 24 hours.
- Recovery time target for a full database restore: 4 hours. This is an internal target, not yet measured in a full restore.
Availability and monitoring
- A public status page shows the state of each component (application, sign-in, email, AI, exports…) and 30 days of incident history.
- Server errors are collected and triaged every day.
- The availability target is set in section 9 of the Terms of Service.
Security practices in place
What is implemented in the product today, not what is planned.
Role-based access control
Platform and organisation roles (admin, manager, user, viewer), checked server-side on every call.
Isolation between organisations
Every organisation-scoped query is filtered by organisation; isolation is covered by automated tests.
Audit log
Sensitive actions logged with before/after changes; SHA-256 chaining makes any tampering detectable.
Two-factor authentication
TOTP with recovery codes, available to every user and mandatory for platform administrators.
Transport and headers
HTTPS only with HSTS, Content-Security-Policy, X-Frame-Options and nosniff. TLS 1.2 minimum in transit, AES-256 at rest at our hosting providers.
Hashed API keys
An API key is shown once, at creation; only its SHA-256 hash is stored.
Rate limiting
Rate limits on API routes and sign-in, origin checks (CSRF) on requests that change data.
Signed webhooks
Timestamped HMAC-SHA256 signature, constant-time comparison and a ±5-minute replay window.
Contract documents
Data Processing Agreement (DPA) with a DORA Art. 30 annex
GDPR Article 28, technical and organisational measures, sub-processor list. Word and PDF, FR and EN.
Privacy policy
Processing, legal bases, retention periods and data subject rights.
Terms of Service
Contractual terms, including the availability target (section 9).
GDPR rights request
Access, rectification, erasure and portability.
Report a vulnerability
We welcome responsible disclosure and take no action against good-faith researchers.
security.txt (RFC 9116)
What we don't have yet
A documented gap beats a badge nobody can check. This list is updated as soon as an item becomes true in production.
No ISO 27001 or SOC 2 certification
ResiPlan holds no ISO 27001, SOC 2 or ISO 22301 certification. The practices above are documented, not audited by a third party.
No SAML SSO or SCIM
SAML SSO and SCIM provisioning are on the roadmap. Sign-in through Microsoft Entra ID or Okta (OpenID Connect) can be enabled on request.
No penetration test report to share
We do not yet have an independent penetration test report we can share with customers.
No SLA with service credits by right
The Terms of Service (section 9) set an availability target, without a numeric contractual commitment backed by penalties.
Status and backups on a single infrastructure
The status page is served by the same infrastructure as the application, and backups are not yet replicated to a second, independent site.
No published customer references yet
ResiPlan is a young product. The scenarios shown on this site are illustrative; we will only publish a reference with the customer's written consent.
A question from your security team?
Security questionnaire, contract clause, architecture question: write to us and we answer with facts.