Security & compliance
Last Updated: 23 September 2026 | Effective Date: 23 September 2026
Our Commitment to Protecting Your Data
We built Critter with security at the core. As a B2B platform trusted by organisations handling critical operations, we take a defence-in-depth approach to safeguarding customer data, ensuring confidentiality, integrity, and availability across every layer of our product and infrastructure.
Security is not an afterthought – it is a foundational part of how we design, build, and operate our systems.
Data Protection & Privacy
Encryption
- In Transit: All customer-facing web and API traffic is encrypted in transit using HTTPS with TLS 1.2+ enforced across all endpoints.
- At Rest: Persistent customer data is protected using platform-managed encryption (AES-256) across databases, object storage, messaging queues, and event streams.
- Secret Management: Application secrets, certificates, and connection strings are managed through dedicated key vaults with strict access controls, soft delete protection, and audit logging.
Multi-Tenancy & Data Isolation
- Customer data is logically segregated using tenant-scoped authorization boundaries.
- Every API request and data query enforces tenant verification to prevent cross-tenant access.
Data Residency & Sub-processors
- Production customer data is hosted in tier-1 cloud regions (in Australia East).
- We maintain a transparent list of third-party sub-processors used to deliver our services, with contractual data protection safeguards established for every provider.
Privacy & Data Processing
- We comply with GDPR requirements in our role as a Data Processor and adhere to privacy-by-design principles.
- A standard Data Processing Addendum (DPA) incorporating standard contractual clauses is available for all customers.
- Customer data is never sold or shared with third parties without contractual necessity or customer instruction.
Data Retention & Deletion
- Data is retained only for the duration of the customer agreement or as required by law.
- Upon account termination, customer data is scheduled for secure deletion and purging across primary data stores and backup cycles according to our retention timeline.
- Customers can export their data upon request prior to account closure.
Application & Product Security
Secure Development Lifecycle (SDLC)
- All code changes undergo mandatory peer review before deployment.
- Continuous integration pipelines include automated secret scanning, test gates, database migration validation, and Infrastructure-as-Code (IaC) security checks.
- Infrastructure is fully managed via audited Infrastructure as Code with automated change validation.
Authentication & Access Controls
- Multi-Factor Authentication (MFA) and Single Sign-On (SSO) are enforced for internal company tools and production infrastructure access.
- Role-Based Access Control (RBAC) and the principle of least privilege are applied across internal operations and service accounts.
Customer-Facing Security Controls
- Granular role-based permissions allowing organization administrators to control member access.
- Session management controls and automatic session expiration.
- Audit logging for administrative and security-sensitive actions within your tenancy.
API Security
- All public and private API endpoints require strong authentication (OAuth 2.0 / token-based authentication).
- Public web and API ingress is protected by a Web Application Firewall (WAF) with rate-limiting rules to mitigate abuse and denial-of-service attempts.
Infrastructure & Cloud Security
Cloud Architecture & Network Isolation
- Hosted with tier-1 cloud providers offering enterprise-grade physical security, environmental controls, and compliance certifications.
- Production environments are logically isolated from development and testing environments.
- Network segmentation, firewalls, and strict ingress/egress rules limit network exposure.
Backups, Business Continuity & Disaster Recovery
- Automated point-in-time recovery and long-term retention policies are configured for production databases.
- Storage systems utilize versioning, soft deletion, and geographic redundancy.
- Regular backup snapshots are maintained for critical event data.
System Availability & Monitoring
- Distributed availability tests continuously monitor production web and API endpoints from multiple geographic locations to ensure uptime and responsiveness.
Security Operations, Incident Response & Testing
Centralized Monitoring & Alerting
- Centralized audit and application logging across all platform services and infrastructure components.
- Automated real-time alerting for anomalous behaviour, authorization failures, and critical system events.
Incident Response
- We maintain a documented Incident Response Plan defining response roles, severity classifications, and escalation paths.
- In the event of a confirmed security incident affecting customer data, impacted customers will be notified promptly in accordance with legal and contractual commitments.
- Post-incident reviews are conducted after major events to identify root causes and implement preventive measures.
Vulnerability Management & Security Assessments
- Automated vulnerability scanning and secret detection run continuously throughout development and deployment.
- Regular security reviews and independent third-party penetration tests are incorporated into our security lifecycle.
Governance, Vendors & Personnel
Vendor Management
- All third-party vendors and critical service providers undergo security and risk assessments prior to onboarding.
- Vendors are required to commit to data protection, security, and confidentiality obligations aligned with our standards.
Personnel Security
- Security awareness training is required for all employees upon joining and periodically thereafter.
- Strict employee onboarding and offboarding workflows ensure access is granted strictly based on role requirements and revoked immediately upon departure.
- Background checks and identity verifications are performed for personnel with access to sensitive systems where legally permissible.
Compliance & Certifications
We align our security practices with leading international security and privacy frameworks:
- GDPR: Compliant as a Data Processor
- SOC 2 Type II: Planned / Alignment in progress
- ISO/IEC 27001: Aligned / On roadmap
Security Resources & Contact
- Privacy Policy: Available at https://getcritter.com/privacy-policy/
- Terms of Service: Available at https://getcritter.com/terms-of-service/
- Data Processing Addendum (DPA): Available upon request
- Sub-processors Register: Available upon request
- Vulnerability Disclosure Policy: Available upon request
- Security Contact: security@crittersoft.com
If you are an enterprise customer or prospect requiring detailed security documentation (security questionnaires, compliance documentation, or architecture reviews), please contact our team to request access.
Continuous Commitment
Security is an ongoing commitment. We regularly review and enhance our technical and organizational measures to adapt to emerging threats, regulatory developments, and customer expectations. If you have any questions about our security posture, our team is available to assist.
