How the service is built, what protects your data, and what we do not claim.
Effective 25 July 2026.
CROapps Oy does not hold a SOC 2 report or an ISO 27001 certificate. We would rather say so here than let a sales conversation discover it later. If your procurement process requires one, tell us: it changes our roadmap, and it is the kind of commitment we would rather make against a real customer than in the abstract.
What we do have is a published Data Processing Addendum incorporating the Standard Contractual Clauses, a complete sub-processor list, and the description below. On Startup and Enterprise we will also answer a security questionnaire and walk your reviewer through the architecture.
The application, object storage, and queues run on Cloudflare. The database is Neon, in the United States. Mail is sent and received through Amazon SES in eu-north-1 (Stockholm), and inbound messages pass through Amazon S3 in the United States on their way to us.
We are a Finnish company and the contract is governed by Finnish law, but the data itself is processed in the United States under the Standard Contractual Clauses. EU data residency is on the roadmap and is not something we offer today. Anyone who tells you otherwise about us is reading an old page; the sub-processor list is the authority.
Every query is scoped to a workspace at the data layer rather than in the interface. An API key resolves to one mailbox in one workspace, and the scoping is asserted by tests that specifically try to read one workspace with another workspace's credentials.
Free mail leaves through a different Amazon SES configuration set and IP pool than paid mail, so a bad free cohort cannot damage the sending reputation of paying customers.
We do not read message content. Abuse enforcement is behavioural: sending velocity, duplicate-content patterns, bounce and complaint rates, and the spam and virus verdicts Amazon SES already attaches. Model or manual review happens only on a workspace that has tripped one of those, only on flagged samples, and only before it is unpaused.
We do not use your data to train models, and we do not sell it or share it for advertising.
On the free plan, messages are kept for 30 days and then deleted, along with the stored objects nothing else points at. Paid plans keep messages until you delete them or close the account.
Abuse-detection records used for duplicate detection are pruned on a rolling window, and the audit trail is kept for 90 days.
Use the contact form and pick the security topic. Tell us what you found and how to reproduce it, and give us a reasonable window to fix it before publishing.
We will confirm receipt, keep you updated, and credit you if you want the credit. We do not run a paid bounty programme, and we will not threaten you for reporting something in good faith.
We notify affected customers of a personal data breach without undue delay and within 48 hours of becoming aware of it, with what happened, what data was involved, and what we are doing about it. That commitment is in the Data Processing Addendum, which is the contractual version of this page.