What happens to a file you send us?
Two sections of the policy below answer that, and they are the ones worth reading before you upload anything: how the application handles your files, and how long each record is kept before it is deleted.
- Section 3 — Customer File handling
- Section 4 — the retention and deletion schedule
- Ask us about a specific board or a security review
The policy below is the authoritative statement; nothing on this page summarises or extends it.
Security, File Retention and Deletion Policy
Version 1.1 · Effective 2026-09-10 · Last updated 2026-09-10 · Operator: Auren LLC
1. Scope and current availability
CROSSPAD is a product operated by Auren LLC. This page describes the security and retention practices that apply to the website and to a deployment in which the migration API is enabled. The public web build may run in preview mode; in that mode a selected file remains in the browser and is not sent to CROSSPAD. A migration is not available unless the deployment explicitly enables the migration API and the account has the required credits.
We do not describe preview behavior as production file processing. Before using a live processing deployment, check the Supported Scope, the report and the notices shown in the application.
2. Controls used by the application
Account and payment security
- Sign-in uses a six-digit email code. Codes are stored as keyed hashes, expire after 10 minutes and are locked after five failed attempts.
- The session cookie is
httpOnly,Securein production andSameSite=Lax, with a seven-day lifetime and server-side revocation. - Card details are entered on Stripe's hosted checkout page. CROSSPAD stores payment references and order records, not card numbers or security codes.
- Server-to-API migration requests use authenticated, time-limited signed headers. Requests without valid production credentials are rejected.
API and worker boundary
- The web application does not run the migration engine. It creates a job through the API and receives the job result asynchronously.
- The API supports a local storage adapter and an S3-compatible adapter. A deployment must use a durable database, durable queue, configured object storage and the container worker mode before it is treated as a production migration deployment.
- The container worker is designed to run without network access, as a non-root user, with a read-only runtime, a job-specific writable directory and resource limits. The subprocess runner is a development or hardened-host option and is not represented as the production isolation boundary.
- Job scratch space is removed after a worker run. A deployment operator is responsible for configuring durable object-storage and database deletion jobs.
- No Customer File is sent to an external AI or machine-learning service, and Customer Files are not used to train models.
Application and infrastructure
- Connections to the website and configured providers use HTTPS/TLS.
- Access to account, order and job records is limited to authenticated application paths and service credentials. The API requires signed internal identity headers in production.
- Vercel hosts the web application and serverless routes. Neon or another configured Postgres service stores web records. The API's storage provider depends on the deployment configuration and is disclosed before it handles live Customer Files.
- Auren LLC has no SOC 2 or ISO 27001 certification and has not commissioned an independent penetration test as of the effective date of this policy.
3. Customer File handling
Customer Files include source files, decisions and other material submitted for a migration. They remain the customer's property. CROSSPAD receives only the material needed to provide the migration service, and Stripe does not receive Customer Files or source file names.
The service does not routinely open Customer Files for human review. If support or remediation requires access, it is limited to the relevant order and handled by personnel bound by confidentiality obligations. Customers must not upload classified, ITAR-controlled or other export-controlled technical data, or data they are not authorized to process in the United States.
4. Retention and deletion
The following schedule applies where the corresponding live processing feature is enabled:
| Record | Retention |
|---|---|
| Analysis-only upload | Deleted within 7 days after the upload or sooner where the deployment does not retain it |
| Source File for an Order | Deleted within 30 days after delivery or order closure, unless earlier deletion is requested after acceptance |
| Delivery Bundle | Available for the 90-day Download Period, then deleted; a non-content hash may be retained |
| Account, order, payment, consent and event records | Up to 7 years after order closure where needed for tax, accounting, fraud and dispute defense |
| Support communications | Up to 3 years |
| Server and edge logs | According to the applicable provider retention setting, ordinarily no more than 90 days |
| Expired codes and sessions | Expired sessions are invalid immediately; stale records are removed during routine cleanup |
To request deletion, email privacy@orkoottrae.resend.app from the Account email and identify the relevant Order Reference. We will confirm the result and explain any records that must be retained by law or for a dispute. Provider backups may persist until their normal rotation expires.
5. Incidents and vulnerability reports
Report a suspected security incident or vulnerability to security@orkoottrae.resend.app. Include enough information to reproduce the issue and do not access, alter or download another customer's data. We acknowledge reports within three business days and investigate in good faith. If a confirmed incident affects Customer Files or personal data, we notify affected customers without undue delay with the information then available and any recommended action.
6. Subprocessors and transfers
The service providers currently used by the web application are Vercel for hosting and serverless execution, Neon for Postgres where configured, Resend for transactional email and Stripe for payments. A live migration deployment may also use an S3-compatible object-storage provider and a worker host; the provider and region are disclosed in the Privacy Policy before live Customer Files are processed. No analytics, advertising or external AI service is used at launch.
Personal data is generally processed in the United States. International-transfer information and data-subject rights are described in the Privacy Policy and, where applicable, the Data Processing Addendum.
7. Limits and customer responsibilities
No system is risk-free. Keep an independent copy of your source design and review every migration result with a qualified engineer before fabrication, assembly, certification or safety-critical use. CROSSPAD is not an archive and does not replace your own backups, access controls or export-control assessment.
We update this policy when the processing architecture, providers or retention schedule changes. A material change is published with a new version and effective date.
8. Contact
Security reports: security@orkoottrae.resend.app<br>
Privacy requests: privacy@orkoottrae.resend.app<br>
Postal address: Auren LLC, 30 N Gould St, STE R, Sheridan, WY 82801, United States
SHA-256 82a42234c83fd87e20589f24b10bba4095afb28a9c5e1b67372911628518ec40
Version 1.1, effective 2026-09-10. Prior versions available on request at legal@orkoottrae.resend.app.