CRODE CRODE

Resources · Security

Security & no-log

The data we never collect is the data we can never lose, leak, or be compelled to hand over. Here is exactly what CRODE collects, retains and destroys — in plain terms, not legalese.

SPEC-01

No-log stance

CRODE products run no analytics scripts, session recorders, or third-party tag managers on any surface. If a feature only works by collecting behavioural data, we don't ship it.

Access logsRetained ≤ 14 days for abuse defence, then rotated and destroyed. No long-term archive.
Product telemetryNone. No usage events, no feature analytics, no fingerprinting.
Third-party trackersZero. No analytics, no ad pixels, no external fonts carrying identifiers.
Customer contentNever inspected. On Crovi, workstation contents are opaque to us by design.

Design rule: the cheapest data to protect is the data that was never collected.

SPEC-02

Encrypted transport

Everything is encrypted in transit and at rest. Session keys are short-lived and rotate automatically; operator access is time-boxed; long-term secrets live in an isolated store, never in config or logs.

In transitTLS 1.3 on every HTTP surface; mutually-authenticated tunnels for agent traffic.
At restVolume-level encryption on all control-plane storage.
KeysRotating session credentials; long-term secrets in an isolated secret store.

SPEC-03

Data lifecycle

Account data is limited to what is required to operate and bill the service. On cancellation, provisioning records and access logs are purged on a fixed schedule — nothing kept "just in case" for resale or model training.

Your exit is clean: request deletion and we destroy account state within 30 days, workloads included. See how the pieces fit together in How it works.