Try free Sign in Contact sales
Trust Center

Security and compliance at Chasa

Chasa is built by a small EU-based team that treats data handling as a first-class feature, not an afterthought. Below is exactly what's true today, and what's next on our compliance roadmap — no inflated claims either way.

What's true today

  • Encryption in transit: every connection to Chasa (app, API, webhooks) runs over TLS/HTTPS.
  • EU-native infrastructure: Chasa runs on Cloudflare's network (Workers, Pages, D1 database, Workers AI), with data at rest protected by our infrastructure provider's standard encryption.
  • Minimal data by design: free, no-account use stores nothing about your invoices on our servers — drafts are generated per request and not retained.
  • Role-based workspace access: Owner, Admin, and Member roles control who can send chases, edit templates, or manage billing.
  • Signed webhooks: outbound webhook payloads are HMAC-signed so receiving systems can verify they came from Chasa.
  • Transparent subprocessors: every third party that touches your data is listed, with the reason we use it, on our Privacy page — nothing undisclosed.
  • EU jurisdiction by default: Chasa is a product of RELACON GmbH in Vienna, Austria — GDPR is our home law, not a bolt-on.
  • No stored third-party credentials: accounting integrations (QuickBooks, Xero) connect via OAuth2 or provider-approved APIs — we never ask for or store your accounting password.

On our compliance roadmap

We're early-stage and building these in the open. None of the items below are live yet — treat this as a roadmap, not a certification claim.

  • SOC2 Type I, then Type II: control design first, then an observation period to test operating effectiveness.
  • ISO 27001 alignment: mapping our controls to Annex A alongside the SOC2 work.
  • Published written policies: Access Control, Encryption, Incident Response, and Vendor Management policies, publicly linked from this page once finalized.
  • Org-wide MFA enforcement policy: a documented, auditable requirement across our own internal systems.
  • Centralized, exportable audit logs: access and admin-action logging across the platform, beyond today's in-app activity history.
  • Evidence-automation connectors: Microsoft Entra ID, GitHub, Slack, and Google Workspace integrations to pull your own access and permission evidence automatically — see evidence automation.
  • Customer-managed encryption keys: planned as an enterprise option.

Our compliance roadmap, by framework

SOC2 evidence automation → Our plan to remove the manual evidence grind from SOC2 audits. ISO 27001 evidence automation → Annex A control evidence, collected instead of screenshotted. Microsoft Entra evidence → Access, group, and MFA evidence exports we're building next. Why evidence automation → The category, and why checks-only compliance tools don't close the gap.

Planning a vendor security review?

Send us your security questionnaire or talk to us directly — we'll answer in plain language, not just checkboxes.

Talk to us about security

See also: Privacy policy · Terms