AI capabilities
Built to the strictest standard, hosted where you choose.
Crunchr was built in Amsterdam under strict European security and privacy standards, and those controls travel wherever it runs — choose the EU or US, and your data stays there exclusively.

Good security starts with knowing where your data is, and knowing it isn’t going anywhere else. That’s not a slogan — it’s a guarantee built into the Crunchr Platform.
Leon Kers
Chief Information Security Officer (CISO) at Crunchr
Audited
SOC 2 Type 2, yearly, by an external firm
Hosted
EU or US region, your choice
AI
Built to stay under your control
Trusted by people-first organisations
Customers
Chosen by teams that ask the hardest questions.
Financial services, insurance, aviation — sectors where security and privacy review is strictest.
European banks and American insurers choose Crunchr because it meets their corporate policies and their industry’s regulatory demands.
These aren’t customers who take compliance claims at face value. They run their own vendor risk assessments, demand evidence over promises, and hold Crunchr to the same standard their regulators demand of them.
Assurance
Verified, not just promised.
Independently audited, tested against real threats, built for GDPR and CCPA/CPRA, and led by named people you can talk to directly.
Audit
SOC 2 Type 2
Crunchr’s controls are examined annually by an independent audit firm, testing both control design and operating effectiveness. The latest SOC 2 Type 2 report is available to customers and prospects on request.
Penetration test
Tested against real threats
An independent security firm performs a yearly penetration test, assessing the Crunchr Platform against realistic, real-world threats. Findings are tracked to resolution through the risk management programme. The latest report is available to customers and prospects on request.
Regulation
GDPR and CCPA/CPRA
The Crunchr Platform is designed to support compliance with GDPR and applicable US state privacy laws, including the CCPA as amended by the CPRA. Documented controls cover anonymisation, data protection, and access management.
Accountability
A named CISO and DPO
Your security and privacy teams can speak to our CISO and Data Protection Officer (DPO) directly during evaluation.
Location
Your data stays where you choose.
One region. Your choice. No exceptions.
One region, no exceptions
The Crunchr Platform is hosted entirely on certified hyperscale infrastructure, in the region you choose — and never leaves it. A full sub-processor list is available to prospects and customers on request.
European Union
Certified hyperscale infrastructure in the EU — Available
United States
Certified hyperscale infrastructure in the US — Available
AI
Artificial Intelligence (AI) built to stay under your control.
Crunchr AI uses standard language models. Only aggregated metrics are sent to them, never individual employee names.
Assistive, not autonomous
AI features surface insights and explanations, but never act or decide on your behalf. They don’t perform profiling, sentiment analysis, or automated decision-making without human oversight.
Permission-aware by design
AI features only surface data a user is already permitted to see. Anonymity thresholds ensure AI analysis never targets or reveals a specific individual.
Never trains on your data, region-locked
Your data is never used to train AI models — processing is inference-only, and runs exclusively on hyperscale infrastructure, within the region you choose.
Yours to keep
You retain ownership of your data, your AI inputs, and any content they generate.
Explainable, and aligned with the EU AI Act
AI features are designed with security, privacy, and robustness measures aligned with the EU AI Act. Any AI output can be reviewed, challenged, or overridden.
Optional, tenant by tenant
Most AI features can be enabled or disabled per customer, at tenant level.
Access controls
Control access down to the field.
Every user sees only the data their role permits, down to the individual field — restricted, suppressed, or masked automatically.
Role-based access
A fine-grained, highly configurable Role-Based Access Control (RBAC) model decides which resources a user reaches and which slice of the data they see inside them.
Anonymity thresholds
Results for groups below your chosen threshold are anonymised, preventing charts from being narrowed to a single employee. You set the threshold; the Crunchr Platform enforces it.
Selective anonymisation
Sensitive fields can be anonymised per role, so a business partner can still analyse pay equity and attrition patterns without ever seeing the individuals behind them.
MFA and SSO
Strong passwords are required. Multi-Factor Authentication (MFA) and Single Sign-On (SSO) are supported via your existing Identity Provider (IdP), using SAML for federation and provisioning — the industry-standard protocol.
Platform
Built for resilience.
Isolated by design, protected at every layer, and ready to scale.
Defence in depth
Crunchr’s defence-in-depth approach ensures strict separation of components, with dedicated, logically isolated infrastructure per customer in a single-tenant model.
Encrypted and backed up
Data is encrypted in transit (TLS 1.2+) and at rest (AES-256), including backups. Backups are automated, immutable, stored off-site, and isolated per customer, with restorability verified through regular disaster recovery testing.
Monitored, 24/7
A dedicated security team monitors the platform’s performance and security around the clock, with critical alerts triaged and routed to trained responders in real time. DDoS protection, a web application firewall, CDN, and secure DNS are provided by a security and performance provider.
Clean environments
Non-production (development, testing) and production environments are kept separate, with only synthetic data used outside production and access to production restricted. Deployments are automated, exceptions are logged and controlled, and data is securely destroyed at the end of its lifecycle.
Incident response
Our incident response process is formalised, with responders standing by around the clock. If there’s any impact on you, we’ll inform you without undue delay.
Scales with you
Horizontal scalability keeps the platform fast and highly available as your headcount and history grow, without complex middleware to integrate new HR systems.
Organisation
The people accountable for security and privacy.
Security and privacy have named executive owners. Behind them is a tech team recruited from top universities with M.Sc. or Ph.D. qualifications in computer science and related fields. Crunchr conducts background checks on all personnel prior to employment.

Leon Kers
Chief Information Security Officer
4+ years at Crunchr, 20+ years in security and audit
Information security leader with experience across consulting, auditing and management. Leon brings both a business and technical perspective to Crunchr’s security programme. Previously CISO at de Volksbank (now: ASN Bank). CISSP and CIPP/E certified, and a registered IT auditor (RE) with NOREA.

Jan Joris Vereijken
Chief Technology Officer (CTO) & DPO
8+ years at Crunchr, 25+ years in security and architecture
End-responsible for technology, with focus on software development, infrastructure, security, scalability, and compliance. As DPO, he oversees Crunchr’s privacy programme. Previously Chief Security Architect at ING. CISSP and CIPP/E certified, and registered with the Dutch Data Protection Authority.
Vulnerability disclosure
If you find something, tell us.
We welcome reports from anyone who finds a vulnerability in our services — customers, security researchers, developers, or anyone else.
FAQ
Common security questions
Only where their role allows it, and often not even then. Role-based access decides what each user reaches, selective anonymisation hides sensitive fields from roles that do not need them, and anonymity thresholds hide any group too small to stay anonymous, so viewers see patterns, not people.
Every user sees only the data their role permits, down to the individual field. A fine-grained Role-Based Access Control (RBAC) model governs which resources a user reaches; anonymity thresholds and selective anonymisation add further protection by suppressing or masking data automatically where needed.
You choose the EU or US as your region — the Crunchr Platform is hosted entirely on hyperscale infrastructure in that region, and your data never leaves it. A full sub-processor list is available to prospects and customers on request.
Crunchr’s defence-in-depth approach ensures strict separation of components, with dedicated, logically isolated infrastructure per customer in a single-tenant model — no customer shares infrastructure with another.
Backups are automated, immutable, and stored off-site, isolated per customer and encrypted using AES-256. Deletion is locked even for Crunchr during the retention period, and restorability is verified through regular disaster recovery testing.
Our SOC 2 Type 2 report and latest penetration test report are available to customers and prospects on request, under a Non-Disclosure Agreement (NDA).
The Crunchr Platform is designed to support compliance with GDPR and applicable US state privacy laws, including the CCPA as amended by the CPRA, with documented controls for anonymisation, data protection, and access management.
Yes. MFA and SSO are supported and recommended using SAML-based federation and automated provisioning with your existing Identity Provider (IdP) — such as Microsoft Entra ID, Active Directory, or Okta.
Upon termination, your data is securely destroyed. You may also choose to receive a copy before it is.
Yes. AI features are bound by the same permission checks as the rest of the Crunchr Platform — a user only sees what their role allows. Anonymity thresholds add a further layer, ensuring AI analysis of a group too small to stay anonymous never singles out an individual.
No — your data is never used to train or fine-tune AI models. Processing is inference-only, and takes place exclusively on hyperscale infrastructure within the region you choose — the same region-lock that applies to the rest of the Crunchr Platform.
Yes. The basis for AI output is made available and traceable, and any output can be reviewed, challenged, or overridden.