Privacy

Privacy by architecture

Your security incident should not become another vendor’s incident database. CRA Report is designed to keep the working incident content on your device.

Operator

CRA Report is operated by Augustin Villetard. This notice explains how information is handled when you use the public website, payment flow and local incident-preparation software.

Incident data

The core application stores assessment answers and report drafts in browser local storage on your device. Report preparation and exports run in your browser. The default application does not send incident descriptions, affected-product details, mitigations, customer information or report contents to CRA Report servers.

No AI processing

The application does not use an AI or large-language-model API to process incident content. Its workflow is based on deterministic application logic and structured templates.

Local storage

Your browser may persist your assessment and draft locally so you can return to the workflow. You can remove that data by clearing site data in your browser. The application also offers an explicit JSON backup for deliberate transfer or retention.

Payments

When checkout is enabled, the payment provider processes payment and billing information under its own privacy terms. CRA Report’s entitlement design only needs signed proof that the incident pack was purchased. Your incident report content is not required for payment verification.

Hosting and technical logs

The public website may be served by a hosting or CDN provider such as Cloudflare. Like most web infrastructure, that provider can process ordinary request metadata such as IP address, requested URL, timestamp and user agent for delivery and security purposes. Incident form content is not included in ordinary static-asset requests.

Analytics

No product analytics SDK is included in the repository by default. If analytics are added later, this notice will be updated before that processing is enabled.

Contact

For privacy questions, data-protection requests or concerns about information handling, contact [email protected]. For legal notices, contact [email protected]. General product and purchase support is available at [email protected].