Resources · Security
Security & no-log
The data we never collect is the data we can never lose, leak, or be compelled to hand over. Here is exactly what CRODE collects, retains and destroys — in plain terms, not legalese.
SPEC-01
No-log stance
CRODE products run no analytics scripts, session recorders, or third-party tag managers on any surface. If a feature only works by collecting behavioural data, we don't ship it.
| Access logs | Retained ≤ 14 days for abuse defence, then rotated and destroyed. No long-term archive. |
|---|---|
| Product telemetry | None. No usage events, no feature analytics, no fingerprinting. |
| Third-party trackers | Zero. No analytics, no ad pixels, no external fonts carrying identifiers. |
| Customer content | Never inspected. On Crovi, workstation contents are opaque to us by design. |
Design rule: the cheapest data to protect is the data that was never collected.
SPEC-02
Encrypted transport
Everything is encrypted in transit and at rest. Session keys are short-lived and rotate automatically; operator access is time-boxed; long-term secrets live in an isolated store, never in config or logs.
| In transit | TLS 1.3 on every HTTP surface; mutually-authenticated tunnels for agent traffic. |
|---|---|
| At rest | Volume-level encryption on all control-plane storage. |
| Keys | Rotating session credentials; long-term secrets in an isolated secret store. |
SPEC-03
Data lifecycle
Account data is limited to what is required to operate and bill the service. On cancellation, provisioning records and access logs are purged on a fixed schedule — nothing kept "just in case" for resale or model training.
Your exit is clean: request deletion and we destroy account state within 30 days, workloads included. See how the pieces fit together in How it works.
CRODE