Trust Center
Security and compliance at Chasa
Chasa is built by a small EU-based team that treats data handling as a first-class feature, not an afterthought. Below is exactly what's true today, and what's next on our compliance roadmap — no inflated claims either way.
What's true today
- Encryption in transit: every connection to Chasa (app, API, webhooks) runs over TLS/HTTPS.
- EU-native infrastructure: Chasa runs on Cloudflare's network (Workers, Pages, D1 database, Workers AI), with data at rest protected by our infrastructure provider's standard encryption.
- Minimal data by design: free, no-account use stores nothing about your invoices on our servers — drafts are generated per request and not retained.
- Role-based workspace access: Owner, Admin, and Member roles control who can send chases, edit templates, or manage billing.
- Signed webhooks: outbound webhook payloads are HMAC-signed so receiving systems can verify they came from Chasa.
- Transparent subprocessors: every third party that touches your data is listed, with the reason we use it, on our Privacy page — nothing undisclosed.
- EU jurisdiction by default: Chasa is a product of RELACON GmbH in Vienna, Austria — GDPR is our home law, not a bolt-on.
- No stored third-party credentials: accounting integrations (QuickBooks, Xero) connect via OAuth2 or provider-approved APIs — we never ask for or store your accounting password.
On our compliance roadmap
We're early-stage and building these in the open. None of the items below are live yet — treat this as a roadmap, not a certification claim.
- SOC2 Type I, then Type II: control design first, then an observation period to test operating effectiveness.
- ISO 27001 alignment: mapping our controls to Annex A alongside the SOC2 work.
- Published written policies: Access Control, Encryption, Incident Response, and Vendor Management policies, publicly linked from this page once finalized.
- Org-wide MFA enforcement policy: a documented, auditable requirement across our own internal systems.
- Centralized, exportable audit logs: access and admin-action logging across the platform, beyond today's in-app activity history.
- Evidence-automation connectors: Microsoft Entra ID, GitHub, Slack, and Google Workspace integrations to pull your own access and permission evidence automatically — see evidence automation.
- Customer-managed encryption keys: planned as an enterprise option.
Our compliance roadmap, by framework
SOC2 evidence automation →
Our plan to remove the manual evidence grind from SOC2 audits.
ISO 27001 evidence automation →
Annex A control evidence, collected instead of screenshotted.
Microsoft Entra evidence →
Access, group, and MFA evidence exports we're building next.
Why evidence automation →
The category, and why checks-only compliance tools don't close the gap.
Planning a vendor security review?
Send us your security questionnaire or talk to us directly — we'll answer in plain language, not just checkboxes.
Talk to us about securitySee also: Privacy policy · Terms