Skip to main content
ResiPlan
Trust Center

Trust: the facts, and only the facts

What procurement, legal and security teams ask before signing. Verifiable facts only, including what we don't have yet.

Publisher

Who publishes ResiPlan

Publisher
Cryptaguard BV
Legal form
Private limited company (BV) under Belgian law
Company number (CBE)
1007.610.660
Registered office
Fazantenlaan 9, 1600 Sint-Pieters-Leeuw, Belgium
Product
ResiPlan
Hosting

Where your data lives, and who processes it

Business data is stored in the European Union. Sub-processors outside the EU are listed below with the safeguards that apply.

Convex

Database, serverless functions, real-time sync and file storage

European Union — AWS eu-west-1 (Ireland), dedicated EU deployment

OVHcloud

Application hosting (web server of the Service)

European Union — France
Sub-processors
Sub-processorScopePurposeData locationTransfer safeguards

Convex

Convex, Inc.

Core serviceDatabase, serverless functions, real-time sync and file storage
European Union — AWS eu-west-1 (Ireland), dedicated EU deployment
Data hosted in the EU; US support access covered by SCCs (2021/914)

OVHcloud

OVH SAS

Core serviceApplication hosting (web server of the Service)
European Union — France
No transfer outside the EU

Resend

Resend, Inc.

Core serviceTransactional email delivery (invitations, notifications, alerts)
United States
SCCs (2021/914)

Stripe

Stripe Payments Europe, Ltd.

Billing (own processing)Subscription payments and billing
European Union, with intra-group transfers to Stripe, Inc. (United States)
SCCs (2021/914) and, where applicable, an active DPF certification

Anthropic

Anthropic, PBC

AI (default)Default AI provider (assistant, plan generation, analyses) — no training on customer data
United States
SCCs (2021/914) and, where applicable, an active DPF certification; per-organization "EU-only AI" option available

OpenAI

OpenAI, L.L.C.

AI (default)Selected AI features and optional cloud transcription of crisis sessions (local alternative available)
United States
SCCs (2021/914) and, where applicable, an active DPF certification; per-organization "EU-only AI" option available

Mistral AI

Mistral AI

AI (EU option)"EU-only AI" option: substitute AI provider configurable per organization
European Union — France
No transfer outside the EU

Plausible Analytics

Plausible Insights OÜ

Core serviceAggregate, cookieless audience measurement (website and application)
European Union
No transfer outside the EU

Google Analytics 4

Google Ireland Limited

Core serviceDetailed audience measurement of the website and application (journeys, traffic sources) — consent-gated
European Union and United States (Google infrastructure)
SCCs (2021/914) and, where applicable, an active DPF certification

Microsoft Clarity

Microsoft Ireland Operations Ltd.

Marketing siteHeatmaps and anonymized session replay on the marketing site — consent-gated
European Union, with possible intra-group transfers to Microsoft Corporation (United States)
SCCs (2021/914) and, where applicable, an active DPF certification

Any new or replaced sub-processor is notified at least 30 days in advance (DPA, section 5.4.2).

Backups and recovery

  • Full, encrypted export of the database every night (AES-256), files included.
  • Retention: 14 daily and 8 weekly backups.
  • Automated restore check every week: decryption, checksum, archive integrity and table census.
  • Recovery point objective (RPO): 24 hours.
  • Recovery time target for a full database restore: 4 hours. This is an internal target, not yet measured in a full restore.

Availability and monitoring

  • A public status page shows the state of each component (application, sign-in, email, AI, exports…) and 30 days of incident history.
  • Server errors are collected and triaged every day.
  • The availability target is set in section 9 of the Terms of Service.
Security

Security practices in place

What is implemented in the product today, not what is planned.

Role-based access control

Platform and organisation roles (admin, manager, user, viewer), checked server-side on every call.

Isolation between organisations

Every organisation-scoped query is filtered by organisation; isolation is covered by automated tests.

Audit log

Sensitive actions logged with before/after changes; SHA-256 chaining makes any tampering detectable.

Two-factor authentication

TOTP with recovery codes, available to every user and mandatory for platform administrators.

Transport and headers

HTTPS only with HSTS, Content-Security-Policy, X-Frame-Options and nosniff. TLS 1.2 minimum in transit, AES-256 at rest at our hosting providers.

Hashed API keys

An API key is shown once, at creation; only its SHA-256 hash is stored.

Rate limiting

Rate limits on API routes and sign-in, origin checks (CSRF) on requests that change data.

Signed webhooks

Timestamped HMAC-SHA256 signature, constant-time comparison and a ±5-minute replay window.

Details on the Security page

Transparency

What we don't have yet

A documented gap beats a badge nobody can check. This list is updated as soon as an item becomes true in production.

No ISO 27001 or SOC 2 certification

ResiPlan holds no ISO 27001, SOC 2 or ISO 22301 certification. The practices above are documented, not audited by a third party.

No SAML SSO or SCIM

SAML SSO and SCIM provisioning are on the roadmap. Sign-in through Microsoft Entra ID or Okta (OpenID Connect) can be enabled on request.

No penetration test report to share

We do not yet have an independent penetration test report we can share with customers.

No SLA with service credits by right

The Terms of Service (section 9) set an availability target, without a numeric contractual commitment backed by penalties.

Status and backups on a single infrastructure

The status page is served by the same infrastructure as the application, and backups are not yet replicated to a second, independent site.

No published customer references yet

ResiPlan is a young product. The scenarios shown on this site are illustrative; we will only publish a reference with the customer's written consent.

A question from your security team?

Security questionnaire, contract clause, architecture question: write to us and we answer with facts.

Trust Center — ResiPlan