Every customer plan ships with full request-level audit logging, KMS-encrypted credentials, IP allowlists, and per-key access scopes. None of it is a Pro-tier upsell — it is the default shape of the service, because the people who buy this product are the people whose jobs are on the line when the answer to "who touched what data, when" is "nobody knows."
This page is honest. Where we have a control, it is documented below with what is actually enforced. Where we don't yet have a certification, it says so.
audit log
actor
access_key_id — UUID of the access key that authorised the call. Resolved from the bearer-token JWT and recorded server-side; cannot be spoofed by the caller.
origin
ip (INET) + request_id. The request_id is honored from a caller-supplied X-Request-Id header or generated server-side, then echoed back so a caller's own trace stack and our audit log share an ID.
operation
op_type (read / write / update / delete / rpc / graphql / schema / auth — constrained by a DB CHECK), plus target (table or procedure name), filter, and column projection.
outcome
status_code (HTTP), duration_ms (server-side latency), rows_affected, and an error string for non-2xx responses. Captured in the same row as the operation — no log correlation required.
append-only
project_crud_logs has a Postgres trigger that blocks UPDATE and DELETE except from a single retention worker that sets a transaction-scoped session variable. The auditor question 'what stops an insider from deleting rows?' has an answer.
retention
30 days on Free Trial, 90 days on Team, 365 days on Business, 730 days on Enterprise by default — configurable per Enterprise contract. Plan-driven retention is enforced by a nightly worker.
export
GET /projects/:id/audit/export?from=&to=&format=json|csv — streams up to 92 days per call. CSV is RFC 4180; JSON is a streamed top-level array. Filename includes the project ID and date range for evidence archival. Self-serve from the dashboard.
streaming (business+)
Per-project sinks for S3 (NDJSON, Athena-partition-friendly key layout), Splunk HEC, and Datadog Logs. Configured in the dashboard, credentials KMS-encrypted at rest, status (last success / last error) visible alongside the configuration.
Logs are queryable from the dashboard and exportable as JSON or CSV for evidence collection. Export endpoints are available on Team and above. On Enterprise, logs can be streamed to your S3, GCS, Splunk HEC, or Datadog endpoint.
access control
per-key scopes
Each access key is bound to one project, a configurable table_scope (CSV of allowed tables — empty = all), a procedure_scope (CSV of allowed stored-procedure names for /rpc/:name calls), an access_type (full or read), and optionally a row_filter expression.
row-level filters
Bind a key to e.g. tenant_id.eq.acme AND status.neq.deleted. The filter is AND-merged into every read/update/delete server-side, validated on every insert row, and applied to predefined queries (including their joined tables). The schema endpoint is restricted to in-scope tables. No leaked key can read, write, or join outside its tenant.
stored procedures (rpc)
POST /rpc/:name calls a stored procedure or function on the customer's database. Procedure names are validated by regex AND looked up in the backend catalog (pg_proc on Postgres) — unknown procs return 404 before any SQL runs. Arguments are bound parameters, never interpolated. Scoped keys must explicitly list allowed procedures in procedure_scope; tenant-scoped keys without that list are refused so they can't escape into arbitrary cross-tenant procs. Postgres is implemented today; SQL Server / Oracle / MySQL stub with 501 — those backends ship next.
fail-closed scope loading
If the API server can't resolve an access key's scope for any reason (DB outage, schema drift), the request is denied with 503 — never silently treated as unrestricted.
IP allowlists
Per-project CIDR allowlists block traffic from anywhere not on the list before the request hits the database.
revocation
Revoking a key invalidates the cached scope within 30 seconds and rejects the next call. Token signature failure is immediate.
graphql + scope
GraphQL queries (both live /graphql and predefined GraphQL queries) are currently refused for scoped keys with HTTP 403. Per-field AST-level scope enforcement is on the roadmap; until then, scoped keys must use the REST endpoints where enforcement is comprehensive.
session model
Dashboard sessions use JWT in HTTP-only cookies + Redis-backed server-side state, so admin logouts are real.
encryption
at rest
Database credentials are encrypted with AES-GCM via AWS KMS. Encrypted blobs live in AWS Secrets Manager; plaintext never touches application disks or logs.
in transit
TLS 1.2+ on every public surface. We hash and pin certificates for outbound connections to your database where you provide the CA bundle.
application logs
Connection strings, secrets, and bearer tokens are stripped before any log line is emitted. Error reports carry redacted query fingerprints, not raw queries.
key custody
On Enterprise, you can supply your own AWS KMS key (BYOK) and revoke it to render your project data unreadable without our involvement.
infrastructure
hosted regions
France (eu-west-3 / Paris) today on Business. Additional regions (other EU, US, APAC) provisioned per Enterprise customer request — we don't pre-spin infrastructure without a customer for it. Once a region is live, data does not cross regions.
dedicated infrastructure
Available on Enterprise — single-tenant cluster, dedicated PostgreSQL for metadata, isolated networking.
byo-vpc / on-prem
Available on Enterprise. The FastCRUD data plane runs in your AWS, GCP, or Azure account. The control plane stays managed; nothing else leaves your perimeter.
network egress
All outbound connections to customer databases happen from a stable, documented IP range, so you can lock down your DB-side firewall.
certifications
SOC 2 Type II
In progress. Type I report available under NDA on request. Type II observation window underway; final report expected Q4 2026.
HIPAA
BAA available on Business and Enterprise plans. Controls mapped to the HIPAA Security Rule § 164.308 / § 164.312.
GDPR
DPA available on all paid plans. EU data plane available on Business. Hungary-headquartered entity (Wood Game Studio Kft.), so GDPR primary supervisory authority is NAIH.
ISO 27001
In scope for FY2027. Not yet certified — don't take our word for it, ask for the SOC 2 report instead.
The compliance posture matters more than the badges in the footer. We'll send you the SOC 2 Type I report under NDA, our current penetration test summary, and our internal control matrix on request.
sub-processors
AWS
Compute, KMS, Secrets Manager, S3 audit-log archive. EU/US regions per customer selection.
Stripe
Self-serve billing only. No card data ever reaches FastCRUD systems.
Cloudflare
Edge TLS, DDoS mitigation on the marketing site and dashboard. Not in the data plane path for API traffic.
SendGrid
Transactional email (verification, billing, sales) — never customer-database content.
The full, current sub-processor list with hosting region details is part of the DPA. Changes are notified 30 days in advance by email to the billing contact on file.
vulnerability disclosure
Email [email protected]. We acknowledge in one business day, triage in three, and patch critical findings inside seven. We will not pursue researchers acting in good faith.
PGP key fingerprint available on request. We don't run a paid bounty program yet — credit is given in release notes for verified findings.
The security questionnaire, SOC 2 Type I report, recent penetration test, and BAA / DPA templates are available under NDA. Email [email protected] and we'll send a packet.