Security & Data Protection

Your process data, fully protected

All production data hosted in the EU. Encrypted in transit and at rest. Built for teams with strict compliance requirements.

EU data residency

All production data stays in the EU

Your process models, transcripts, and workspace data are hosted exclusively in European data centers. Authentication is managed globally by Firebase Auth (Google Cloud), but all user-created content stays within EU borders.

  • All user-created content stored in EU data centers
  • Supports GDPR data residency requirements
ServiceLocation
Database (Firestore)EU multi-region
File storageEU dual-region
Application serversEU
AuthenticationGlobal

Data encryption

What's encrypted

All data is encrypted at rest with AES-256. Teams and Enterprise plans add field-level encryption: your BPMN diagrams, transcripts, and chat messages are encrypted before they reach storage.

Encrypted at application layer (Teams+)

  • BPMN diagrams (XML)

    Encrypted before storage, decrypted on load

  • Meeting transcripts

    Encrypted at upload, decrypted for AI processing

  • AI chat messages (Design Sessions)

    Each message encrypted individually

  • Version history (Milestones)

    Historical snapshots encrypted

  • Shared diagrams

    Decrypted only for authorized viewers

Standard protection (all plans)

  • User profiles & settings

    Google-managed AES-256

  • Billing information

    Handled entirely by Stripe, never touches Crismo

Plan comparison

Security features by plan

Core protections are included on every plan. Advanced features like field-level encryption and customer-managed keys are available on Teams and Enterprise.

FeatureFreeProTeamsEnterprise
EU data residency
Encryption at rest (AES-256)
Encryption in transit (TLS)
Security headers
Field-level encryption
Customer-managed keys (CMEK)

Transparent encryption

Encryption your team never has to think about

Encryption and decryption happen automatically. Your team doesn't need to manage keys, enter passwords, or change how they work. Diagrams, transcripts, and chat messages are encrypted before storage and decrypted on load.

Create or edit

Browser

Encrypt

Server

Store encrypted

EU storage

Security FAQ

Start with enterprise-grade security on day one

EU hosting and encryption at rest are included on every plan. No setup, no add-ons.