• Pricing
  • Customers
  • Changelog
Login Get started
IntegrationsPricingCustomersChangelogDocsBlogHelp
Login Get started

Security & compliance

Safe, secure, and private.

Cradl AI is built with best-in-class security practices to keep your work safe and secure at every layer. This includes state-of-the-art encryption, safe and reliable infrastructure partners, and independently verified security controls.

Security details

Cradl AI is hosted on Amazon Web Services (AWS), allowing us to leverage AWS's industry-leading physical security, redundancy, scalability, and key management capabilities. Our infrastructure is cloud-native, and we use managed AWS services wherever possible to reduce operational complexity and minimize the attack surface of software managed by Cradl AI.

All data in transit, including inter-VPC communication, is encrypted using TLS. Data at rest is encrypted using AES-256 in GCM mode, in accordance with AWS best practices. Encryption keys are managed using AWS Key Management Service (KMS), with unique encryption keys per account. All TLS certificates are managed through AWS Certificate Manager (ACM).

Customers define how long documents submitted to Cradl AI are retained using configurable data retention policies. Documents are automatically deleted once the retention period expires.

Cradl AI uses a limited number of third-party service providers for infrastructure, analytics, payments, and transactional emails.

Cradl AI is deployed across multiple AWS availability zones and is continuously monitored to detect and respond to failures. We use Amazon API Gateway's built-in DDoS protection and request throttling to prevent abuse. Automated health checks are run continuously, and unhealthy instances are automatically replaced. Our service commitments are governed by our Service Level Agreement (SLA).

Cradl AI undergoes regular security testing, including external security assessments. We also leverage AWS security services such as CloudTrail, WAF, GuardDuty, as well as dependency scanning tools like Snyk to detect vulnerabilities and security risks. While we continuously work to maintain a high level of security, no system is completely immune to vulnerabilities. If you believe you have discovered a security issue, we encourage responsible disclosure so we can investigate and remediate it promptly.

Security at Cradl AI extends beyond our application and infrastructure. We maintain internal security policies covering access control, incident management, and operational security. Details of internal physical security and employee procedures are not disclosed publicly.

Employees have unique accounts for all business-critical systems. Multi-factor authentication is enforced wherever possible, and access is granted strictly according to the principle of least privilege.

Cradl AI follows the principle of immutable infrastructure. Developers do not have direct access to production environments or customer data stores.

All Cradl AI employees are based in Europe (Norway). Employee laptops use full-disk encryption, and additional security precautions are taken when traveling to higher-risk regions.

Have more questions?

Book a call to know more.

Book call

Start today

Agentic document automation.

Start extracting data from your documents in minutes - no credit card required. Scale when you're ready.

Start for freeTalk to sales
Cradl AI

Document processing on autopilot.

Platform

  • Home
  • Integrations
  • Customers
  • Pricing

Resources

  • Blog
  • Contact
  • Solutions
  • Documentation

Legal

  • Terms of Service
  • Privacy Policy
  • Security
  • Contact

Contact

  • Email us
  • Support
  • LinkedIn
  • Book a demo

© 2026 Cradl AI

Privacy PolicyTerms of ServiceSecurityContact