$fastcrud
~ security & compliance

The audit log is the product.

Every customer plan ships with full request-level audit logging, KMS-encrypted credentials, IP allowlists, and per-key access scopes. None of it is a Pro-tier upsell — it is the default shape of the service, because the people who buy this product are the people whose jobs are on the line when the answer to "who touched what data, when" is "nobody knows."

This page is honest. Where we have a control, it is documented below with what is actually enforced. Where we don't yet have a certification, it says so.

audit log

#what we record on every call

actor

access_key_id — UUID of the access key that authorised the call. Resolved from the bearer-token JWT and recorded server-side; cannot be spoofed by the caller.

origin

ip (INET) + request_id. The request_id is honored from a caller-supplied X-Request-Id header or generated server-side, then echoed back so a caller's own trace stack and our audit log share an ID.

operation

op_type (read / write / update / delete / rpc / graphql / schema / auth — constrained by a DB CHECK), plus target (table or procedure name), filter, and column projection.

outcome

status_code (HTTP), duration_ms (server-side latency), rows_affected, and an error string for non-2xx responses. Captured in the same row as the operation — no log correlation required.

append-only

project_crud_logs has a Postgres trigger that blocks UPDATE and DELETE except from a single retention worker that sets a transaction-scoped session variable. The auditor question 'what stops an insider from deleting rows?' has an answer.

retention

30 days on Free Trial, 90 days on Team, 365 days on Business, 730 days on Enterprise by default — configurable per Enterprise contract. Plan-driven retention is enforced by a nightly worker.

export

GET /projects/:id/audit/export?from=&to=&format=json|csv — streams up to 92 days per call. CSV is RFC 4180; JSON is a streamed top-level array. Filename includes the project ID and date range for evidence archival. Self-serve from the dashboard.

streaming (business+)

Per-project sinks for S3 (NDJSON, Athena-partition-friendly key layout), Splunk HEC, and Datadog Logs. Configured in the dashboard, credentials KMS-encrypted at rest, status (last success / last error) visible alongside the configuration.

Logs are queryable from the dashboard and exportable as JSON or CSV for evidence collection. Export endpoints are available on Team and above. On Enterprise, logs can be streamed to your S3, GCS, Splunk HEC, or Datadog endpoint.

access control

#who can do what

per-key scopes

Each access key is bound to one project, a configurable table_scope (CSV of allowed tables — empty = all), a procedure_scope (CSV of allowed stored-procedure names for /rpc/:name calls), an access_type (full or read), and optionally a row_filter expression.

row-level filters

Bind a key to e.g. tenant_id.eq.acme AND status.neq.deleted. The filter is AND-merged into every read/update/delete server-side, validated on every insert row, and applied to predefined queries (including their joined tables). The schema endpoint is restricted to in-scope tables. No leaked key can read, write, or join outside its tenant.

stored procedures (rpc)

POST /rpc/:name calls a stored procedure or function on the customer's database. Procedure names are validated by regex AND looked up in the backend catalog (pg_proc on Postgres) — unknown procs return 404 before any SQL runs. Arguments are bound parameters, never interpolated. Scoped keys must explicitly list allowed procedures in procedure_scope; tenant-scoped keys without that list are refused so they can't escape into arbitrary cross-tenant procs. Postgres is implemented today; SQL Server / Oracle / MySQL stub with 501 — those backends ship next.

fail-closed scope loading

If the API server can't resolve an access key's scope for any reason (DB outage, schema drift), the request is denied with 503 — never silently treated as unrestricted.

IP allowlists

Per-project CIDR allowlists block traffic from anywhere not on the list before the request hits the database.

revocation

Revoking a key invalidates the cached scope within 30 seconds and rejects the next call. Token signature failure is immediate.

graphql + scope

GraphQL queries (both live /graphql and predefined GraphQL queries) are currently refused for scoped keys with HTTP 403. Per-field AST-level scope enforcement is on the roadmap; until then, scoped keys must use the REST endpoints where enforcement is comprehensive.

session model

Dashboard sessions use JWT in HTTP-only cookies + Redis-backed server-side state, so admin logouts are real.

encryption

#credentials never travel as plaintext

at rest

Database credentials are encrypted with AES-GCM via AWS KMS. Encrypted blobs live in AWS Secrets Manager; plaintext never touches application disks or logs.

in transit

TLS 1.2+ on every public surface. We hash and pin certificates for outbound connections to your database where you provide the CA bundle.

application logs

Connection strings, secrets, and bearer tokens are stripped before any log line is emitted. Error reports carry redacted query fingerprints, not raw queries.

key custody

On Enterprise, you can supply your own AWS KMS key (BYOK) and revoke it to render your project data unreadable without our involvement.

infrastructure

#where your data plane runs

hosted regions

France (eu-west-3 / Paris) today on Business. Additional regions (other EU, US, APAC) provisioned per Enterprise customer request — we don't pre-spin infrastructure without a customer for it. Once a region is live, data does not cross regions.

dedicated infrastructure

Available on Enterprise — single-tenant cluster, dedicated PostgreSQL for metadata, isolated networking.

byo-vpc / on-prem

Available on Enterprise. The FastCRUD data plane runs in your AWS, GCP, or Azure account. The control plane stays managed; nothing else leaves your perimeter.

network egress

All outbound connections to customer databases happen from a stable, documented IP range, so you can lock down your DB-side firewall.

certifications

#what we have, and what we don't

SOC 2 Type II

In progress. Type I report available under NDA on request. Type II observation window underway; final report expected Q4 2026.

HIPAA

BAA available on Business and Enterprise plans. Controls mapped to the HIPAA Security Rule § 164.308 / § 164.312.

GDPR

DPA available on all paid plans. EU data plane available on Business. Hungary-headquartered entity (Wood Game Studio Kft.), so GDPR primary supervisory authority is NAIH.

ISO 27001

In scope for FY2027. Not yet certified — don't take our word for it, ask for the SOC 2 report instead.

The compliance posture matters more than the badges in the footer. We'll send you the SOC 2 Type I report under NDA, our current penetration test summary, and our internal control matrix on request.

sub-processors

#who else touches the data path

AWS

Compute, KMS, Secrets Manager, S3 audit-log archive. EU/US regions per customer selection.

Stripe

Self-serve billing only. No card data ever reaches FastCRUD systems.

Cloudflare

Edge TLS, DDoS mitigation on the marketing site and dashboard. Not in the data plane path for API traffic.

SendGrid

Transactional email (verification, billing, sales) — never customer-database content.

The full, current sub-processor list with hosting region details is part of the DPA. Changes are notified 30 days in advance by email to the billing contact on file.

vulnerability disclosure

#how to report a finding

Email [email protected]. We acknowledge in one business day, triage in three, and patch critical findings inside seven. We will not pursue researchers acting in good faith.

PGP key fingerprint available on request. We don't run a paid bounty program yet — credit is given in release notes for verified findings.

$ want the long-form version?

The security questionnaire, SOC 2 Type I report, recent penetration test, and BAA / DPA templates are available under NDA. Email [email protected] and we'll send a packet.