Skip to main content

What happens to a file you send us?

Two sections of the policy below answer that, and they are the ones worth reading before you upload anything: how the application handles your files, and how long each record is kept before it is deleted.

The policy below is the authoritative statement; nothing on this page summarises or extends it.

TRUST · SECURITY AND RETENTION

Security, File Retention and Deletion Policy

Version 1.1 · Effective 2026-09-10 · Last updated 2026-09-10 · Operator: Auren LLC

1. Scope and current availability

CROSSPAD is a product operated by Auren LLC. This page describes the security and retention practices that apply to the website and to a deployment in which the migration API is enabled. The public web build may run in preview mode; in that mode a selected file remains in the browser and is not sent to CROSSPAD. A migration is not available unless the deployment explicitly enables the migration API and the account has the required credits.

We do not describe preview behavior as production file processing. Before using a live processing deployment, check the Supported Scope, the report and the notices shown in the application.

2. Controls used by the application

Account and payment security

  • Sign-in uses a six-digit email code. Codes are stored as keyed hashes, expire after 10 minutes and are locked after five failed attempts.
  • The session cookie is httpOnly, Secure in production and SameSite=Lax, with a seven-day lifetime and server-side revocation.
  • Card details are entered on Stripe's hosted checkout page. CROSSPAD stores payment references and order records, not card numbers or security codes.
  • Server-to-API migration requests use authenticated, time-limited signed headers. Requests without valid production credentials are rejected.

API and worker boundary

  • The web application does not run the migration engine. It creates a job through the API and receives the job result asynchronously.
  • The API supports a local storage adapter and an S3-compatible adapter. A deployment must use a durable database, durable queue, configured object storage and the container worker mode before it is treated as a production migration deployment.
  • The container worker is designed to run without network access, as a non-root user, with a read-only runtime, a job-specific writable directory and resource limits. The subprocess runner is a development or hardened-host option and is not represented as the production isolation boundary.
  • Job scratch space is removed after a worker run. A deployment operator is responsible for configuring durable object-storage and database deletion jobs.
  • No Customer File is sent to an external AI or machine-learning service, and Customer Files are not used to train models.

Application and infrastructure

  • Connections to the website and configured providers use HTTPS/TLS.
  • Access to account, order and job records is limited to authenticated application paths and service credentials. The API requires signed internal identity headers in production.
  • Vercel hosts the web application and serverless routes. Neon or another configured Postgres service stores web records. The API's storage provider depends on the deployment configuration and is disclosed before it handles live Customer Files.
  • Auren LLC has no SOC 2 or ISO 27001 certification and has not commissioned an independent penetration test as of the effective date of this policy.

3. Customer File handling

Customer Files include source files, decisions and other material submitted for a migration. They remain the customer's property. CROSSPAD receives only the material needed to provide the migration service, and Stripe does not receive Customer Files or source file names.

The service does not routinely open Customer Files for human review. If support or remediation requires access, it is limited to the relevant order and handled by personnel bound by confidentiality obligations. Customers must not upload classified, ITAR-controlled or other export-controlled technical data, or data they are not authorized to process in the United States.

4. Retention and deletion

The following schedule applies where the corresponding live processing feature is enabled:

RecordRetention
Analysis-only uploadDeleted within 7 days after the upload or sooner where the deployment does not retain it
Source File for an OrderDeleted within 30 days after delivery or order closure, unless earlier deletion is requested after acceptance
Delivery BundleAvailable for the 90-day Download Period, then deleted; a non-content hash may be retained
Account, order, payment, consent and event recordsUp to 7 years after order closure where needed for tax, accounting, fraud and dispute defense
Support communicationsUp to 3 years
Server and edge logsAccording to the applicable provider retention setting, ordinarily no more than 90 days
Expired codes and sessionsExpired sessions are invalid immediately; stale records are removed during routine cleanup

To request deletion, email privacy@orkoottrae.resend.app from the Account email and identify the relevant Order Reference. We will confirm the result and explain any records that must be retained by law or for a dispute. Provider backups may persist until their normal rotation expires.

5. Incidents and vulnerability reports

Report a suspected security incident or vulnerability to security@orkoottrae.resend.app. Include enough information to reproduce the issue and do not access, alter or download another customer's data. We acknowledge reports within three business days and investigate in good faith. If a confirmed incident affects Customer Files or personal data, we notify affected customers without undue delay with the information then available and any recommended action.

6. Subprocessors and transfers

The service providers currently used by the web application are Vercel for hosting and serverless execution, Neon for Postgres where configured, Resend for transactional email and Stripe for payments. A live migration deployment may also use an S3-compatible object-storage provider and a worker host; the provider and region are disclosed in the Privacy Policy before live Customer Files are processed. No analytics, advertising or external AI service is used at launch.

Personal data is generally processed in the United States. International-transfer information and data-subject rights are described in the Privacy Policy and, where applicable, the Data Processing Addendum.

7. Limits and customer responsibilities

No system is risk-free. Keep an independent copy of your source design and review every migration result with a qualified engineer before fabrication, assembly, certification or safety-critical use. CROSSPAD is not an archive and does not replace your own backups, access controls or export-control assessment.

We update this policy when the processing architecture, providers or retention schedule changes. A material change is published with a new version and effective date.

8. Contact

Security reports: security@orkoottrae.resend.app<br> Privacy requests: privacy@orkoottrae.resend.app<br> Postal address: Auren LLC, 30 N Gould St, STE R, Sheridan, WY 82801, United States

SHA-256 82a42234c83fd87e20589f24b10bba4095afb28a9c5e1b67372911628518ec40

Version 1.1, effective 2026-09-10. Prior versions available on request at legal@orkoottrae.resend.app.