Trust
Trust & security
Version 2026-08-12 · Operational summary for procurement and security review. Contacts: info@centropic.ai
1. Controls
- Signed sessions, CSRF on state-changing forms, CSP with nonce, hashed passwords.
- Tenant isolation on queries (user_id / organization).
- Paddle webhooks with signature verification; fail-closed billing on insufficient credit.
- SSRF guard on analyzed URLs; rate limits on sensitive actions.
2. Sub-processors
Active list and downloadable Art. 28 DPA: DPA / Sub-processors · Download .txt.
3. Retention
- Account and results: while the account is active + technical post-closure periods (backup/security).
- Analysis packs/object storage: typically 90 days (configurable).
- Technical security logs: as long as necessary for abuse prevention and debugging.
- Credit / billing ledger: accounting and anti-fraud obligations.
4. Rights and Incidents
Export/delete from Account Settings. For data breaches or privacy requests: info@centropic.ai. We aim to respond to data subject requests within 30 days, unless complexity requires more time.