Your process data, fully protected
All production data hosted in the EU. Encrypted in transit and at rest. Built for teams with strict compliance requirements.
EU data residency
All production data stays in the EU
Your process models, transcripts, and workspace data are hosted exclusively in European data centers. Authentication is managed globally by Firebase Auth (Google Cloud), but all user-created content stays within EU borders.
- All user-created content stored in EU data centers
- Supports GDPR data residency requirements
| Service | Location |
|---|---|
| Database (Firestore) | EU multi-region |
| File storage | EU dual-region |
| Application servers | EU |
| Authentication | Global |
Data encryption
What's encrypted
All data is encrypted at rest with AES-256. Teams and Enterprise plans add field-level encryption: your BPMN diagrams, transcripts, and chat messages are encrypted before they reach storage.
Encrypted at application layer (Teams+)
BPMN diagrams (XML)
Encrypted before storage, decrypted on load
Meeting transcripts
Encrypted at upload, decrypted for AI processing
AI chat messages (Design Sessions)
Each message encrypted individually
Version history (Milestones)
Historical snapshots encrypted
Shared diagrams
Decrypted only for authorized viewers
Standard protection (all plans)
User profiles & settings
Google-managed AES-256
Billing information
Handled entirely by Stripe, never touches Crismo
Plan comparison
Security features by plan
Core protections are included on every plan. Advanced features like field-level encryption and customer-managed keys are available on Teams and Enterprise.
| Feature | Free | Pro | Teams | Enterprise |
|---|---|---|---|---|
| EU data residency | ||||
| Encryption at rest (AES-256) | ||||
| Encryption in transit (TLS) | ||||
| Security headers | ||||
| Field-level encryption | ||||
| Customer-managed keys (CMEK) |
Transparent encryption
Encryption your team never has to think about
Encryption and decryption happen automatically. Your team doesn't need to manage keys, enter passwords, or change how they work. Diagrams, transcripts, and chat messages are encrypted before storage and decrypted on load.
Create or edit
Browser
Encrypt
Server
Store encrypted
EU storage
Security FAQ
Start with enterprise-grade security on day one
EU hosting and encryption at rest are included on every plan. No setup, no add-ons.