Built to the strictest standard, hosted where you choose.

Leon Kers

Trusted by people-first organisations

Customers

Chosen by teams that ask the hardest questions.

Financial services, insurance, aviation — sectors where security and privacy review is strictest.

European banks and American insurers choose Crunchr because it meets their corporate policies and their industry’s regulatory demands.

These aren’t customers who take compliance claims at face value. They run their own vendor risk assessments, demand evidence over promises, and hold Crunchr to the same standard their regulators demand of them.

Assurance

Verified, not just promised.


Independently audited, tested against real threats, built for GDPR and CCPA/CPRA, and led by named people you can talk to directly.

Audit

SOC 2 Type 2

Crunchr’s controls are examined annually by an independent audit firm, testing both control design and operating effectiveness. The latest SOC 2 Type 2 report is available to customers and prospects on request.

Penetration test

Tested against real threats

An independent security firm performs a yearly penetration test, assessing the Crunchr Platform against realistic, real-world threats. Findings are tracked to resolution through the risk management programme. The latest report is available to customers and prospects on request.

Regulation

GDPR and CCPA/CPRA

The Crunchr Platform is designed to support compliance with GDPR and applicable US state privacy laws, including the CCPA as amended by the CPRA. Documented controls cover anonymisation, data protection, and access management.

Accountability

A named CISO and DPO

Your security and privacy teams can speak to our CISO and Data Protection Officer (DPO) directly during evaluation.

Location

Your data stays where you choose.

One region. Your choice. No exceptions.

One region, no exceptions

The Crunchr Platform is hosted entirely on certified hyperscale infrastructure, in the region you choose — and never leaves it. A full sub-processor list is available to prospects and customers on request.

European Union

Certified hyperscale infrastructure in the EU — Available

United States

Certified hyperscale infrastructure in the US — Available

AI

Artificial Intelligence (AI) built to stay under your control.

Crunchr AI uses standard language models. Only aggregated metrics are sent to them, never individual employee names.

Assistive, not autonomous 

AI features surface insights and explanations, but never act or decide on your behalf. They don’t perform profiling, sentiment analysis, or automated decision-making without human oversight.

Permission-aware by design

AI features only surface data a user is already permitted to see. Anonymity thresholds ensure AI analysis never targets or reveals a specific individual.

Never trains on your data, region-locked

Your data is never used to train AI models — processing is inference-only, and runs exclusively on hyperscale infrastructure, within the region you choose.

Yours to keep

You retain ownership of your data, your AI inputs, and any content they generate.

Explainable, and aligned with the EU AI Act

AI features are designed with security, privacy, and robustness measures aligned with the EU AI Act. Any AI output can be reviewed, challenged, or overridden.

Optional, tenant by tenant

Most AI features can be enabled or disabled per customer, at tenant level.

Platform

Built for resilience.

Isolated by design, protected at every layer, and ready to scale.

Defence in depth

Crunchr’s defence-in-depth approach ensures strict separation of components, with dedicated, logically isolated infrastructure per customer in a single-tenant model.

Encrypted and backed up

Data is encrypted in transit (TLS 1.2+) and at rest (AES-256), including backups. Backups are automated, immutable, stored off-site, and isolated per customer, with restorability verified through regular disaster recovery testing.

Monitored, 24/7

A dedicated security team monitors the platform’s performance and security around the clock, with critical alerts triaged and routed to trained responders in real time. DDoS protection, a web application firewall, CDN, and secure DNS are provided by a security and performance provider.

Clean environments

Non-production (development, testing) and production environments are kept separate, with only synthetic data used outside production and access to production restricted. Deployments are automated, exceptions are logged and controlled, and data is securely destroyed at the end of its lifecycle.

Incident response

Our incident response process is formalised, with responders standing by around the clock. If there’s any impact on you, we’ll inform you without undue delay.

Scales with you

Horizontal scalability keeps the platform fast and highly available as your headcount and history grow, without complex middleware to integrate new HR systems.

Organisation

The people accountable for security and privacy.

Security and privacy have named executive owners. Behind them is a tech team recruited from top universities with M.Sc. or Ph.D. qualifications in computer science and related fields. Crunchr conducts background checks on all personnel prior to employment.

Leon Kers

Chief Information Security Officer

4+ years at Crunchr, 20+ years in security and audit

Jan Joris Vereijken

Chief Technology Officer (CTO) & DPO

8+ years at Crunchr, 25+ years in security and architecture

Vulnerability disclosure

If you find something, tell us.

We welcome reports from anyone who finds a vulnerability in our services — customers, security researchers, developers, or anyone else.

FAQ

Common security questions

Can anyone see an individual employee’s data?

Only where their role allows it, and often not even then. Role-based access decides what each user reaches, selective anonymisation hides sensitive fields from roles that do not need them, and anonymity thresholds hide any group too small to stay anonymous, so viewers see patterns, not people.

What’s the access control model?

Every user sees only the data their role permits, down to the individual field. A fine-grained Role-Based Access Control (RBAC) model governs which resources a user reaches; anonymity thresholds and selective anonymisation add further protection by suppressing or masking data automatically where needed.

Where is our data stored, and can it move?

You choose the EU or US as your region — the Crunchr Platform is hosted entirely on hyperscale infrastructure in that region, and your data never leaves it. A full sub-processor list is available to prospects and customers on request.

How is tenancy and component isolation handled?

Crunchr’s defence-in-depth approach ensures strict separation of components, with dedicated, logically isolated infrastructure per customer in a single-tenant model — no customer shares infrastructure with another.

How are backups managed, and how often is disaster recovery tested?

Backups are automated, immutable, and stored off-site, isolated per customer and encrypted using AES-256. Deletion is locked even for Crunchr during the retention period, and restorability is verified through regular disaster recovery testing.

Which certifications and reports can we see?

Our SOC 2 Type 2 report and latest penetration test report are available to customers and prospects on request, under a Non-Disclosure Agreement (NDA).

Does Crunchr meet GDPR and US state privacy law?

The Crunchr Platform is designed to support compliance with GDPR and applicable US state privacy laws, including the CCPA as amended by the CPRA, with documented controls for anonymisation, data protection, and access management.

Can we use our own MFA and SSO?

Yes. MFA and SSO are supported and recommended using SAML-based federation and automated provisioning with your existing Identity Provider (IdP) — such as Microsoft Entra ID, Active Directory, or Okta.

What happens to our data when the contract ends?

Upon termination, your data is securely destroyed. You may also choose to receive a copy before it is.

Does Crunchr’s AI respect the same access permissions as the rest of the platform?

Yes. AI features are bound by the same permission checks as the rest of the Crunchr Platform — a user only sees what their role allows. Anonymity thresholds add a further layer, ensuring AI analysis of a group too small to stay anonymous never singles out an individual.

Where does AI processing happen, and is our data used to train models?

No — your data is never used to train or fine-tune AI models. Processing is inference-only, and takes place exclusively on hyperscale infrastructure within the region you choose — the same region-lock that applies to the rest of the Crunchr Platform.

Can we trace how an AI feature produced a specific output?

Yes. The basis for AI output is made available and traceable, and any output can be reviewed, challenged, or overridden.