As your authorised representative under the Cyber Resilience Act, we hold your EU Declaration of Conformity and technical documentation — which may contain trade secrets — for the statutory retention period. Protecting that documentation is central to our service. This page explains, in plain terms, how we do it.
Our application and database run on infrastructure hosted in the EU (Germany), within the EU/EEA. Your uploaded documents are kept in dedicated object storage that encrypts every object at rest. Your data does not need to leave the EU to be managed.
Access to the portal requires authentication, and it is role-based: each client organisation sees only its own data. Every reasoned request from a market-surveillance authority is logged with a complete audit trail — when it arrived, what was provided, and when we responded. Statutory documents are held under a tamper-evident 10-year retention lock, so they cannot be silently altered or deleted within the period the CRA requires.
We are GDPR-compliant and provide a Data Processing Agreement (DPA) on request. Every mandate includes a confidentiality clause, and we are glad to sign a separate non-disclosure agreement (NDA). Our information-security practices follow the principles of ISO/IEC 27001 (information-security management). We are an early-stage provider and are not yet certified; certification is on our roadmap.
You decide what is uploaded. You can request an export of your data at any time, or its deletion — subject only to the statutory retention obligations that the CRA places on the representative role.
Questions about how we handle your data? Get in touch — we are happy to walk you or your advisers through the details.