Data processing agreement
Article 28 terms, published rather than negotiated.
Security buyers ask for a DPA before they ask about features. Here it is in public, so procurement can read it without signing anything first.
2A2M SIA · Latvia · last updated 2 September 2026
1Roles and scope
This agreement applies where 2A2M SIA processes personal data on your behalf, and forms part of the terms of service. You are the controller; we are the processor. It takes effect when you begin using Cidra and lasts as long as we hold your data.
Subject matter: providing software composition, binary, API and website assurance. Duration: the life of the account. Nature and purpose: analysing material you submit to produce security findings. Categories of data subject: your personnel who hold accounts, and any individuals whose personal data incidentally appears in material you upload. Types of data: names, work email addresses, and whatever is contained in the inventories and artefacts you choose to submit.
2Our obligations
- We process personal data only on your documented instructions, of which using the product is one, unless law requires otherwise — in which case we tell you first unless that law forbids it.
- Everyone with access is bound by confidentiality.
- We assist you with data subject requests, with security obligations, and with impact assessments, so far as is reasonable.
- On termination we delete your data within 30 days, or return it, at your choice.
- We make available the information needed to demonstrate compliance and will accept a reasonable audit, once a year or after a breach.
3Sub-processors
The complete list, and what each one actually touches:
- MongoDB Atlas (Ireland) — database hosting. Sees all stored data.
- DigitalOcean (Frankfurt, Germany) — application hosting. Sees data in transit and in memory.
- Stripe (Ireland) — payments. Sees billing identity and card data; sees nothing from your workspace.
- Brevo (France) — transactional email. Sees the recipient address and the message.
We will give at least 30 days’ notice by email before adding or replacing a sub-processor. If you object on reasonable data protection grounds and we cannot resolve it, you may terminate without penalty and receive a pro-rata refund.
4Security measures
The technical and organisational measures under Article 32. These are the measures actually in place, not an aspiration:
- TLS 1.2 or better for all traffic, with HSTS.
- Passwords hashed with scrypt. Session tokens stored only as SHA-256 hashes, with absolute and idle expiry and immediate revocation on sign-out.
- Brute-force protection on sign-in, with per-account and per-source limits.
- Tenant isolation enforced server-side on every request. Membership is re-checked in the server component that renders each page, not only in middleware.
- Role-based access within a workspace, with billing restricted to the workspace lead.
- A hash-chained, append-only audit log whose integrity can be verified.
- Uploaded binaries and API contracts are analysed under strict size limits and discarded after the request. Credential-shaped strings are redacted before they reach a finding.
- Secrets held server-side only, never in client code.
Two things we do not yet claim, because claiming them would be false: we hold no ISO 27001 or SOC 2 certification, and we do not encrypt individual fields at rest beyond the encryption our hosting providers apply at volume level.
5Breach notification
We notify you without undue delay, and within 72 hours of becoming aware, of any breach affecting your personal data — including what happened, which categories and roughly how many records are involved, the likely consequences and what we are doing about it. If we do not yet know all of that, we tell you what we do know rather than waiting until the picture is complete.
6International transfers
Primary processing is in the EEA. Where a sub-processor transfers data outside it, that transfer relies on the European Commission’s standard contractual clauses, which are incorporated here by reference.
7Signature
Most customers need this on file rather than negotiated. If you need a counter-signed copy, or your own paper instead of ours, write to privacy@cidra.dev and we will sign.