Security and compliance
Short answer: your data stays in the EU, each company sees only its own records, every decision is signed with the user's own password, and the audit trail is built so that a changed or missing entry is detected. ColdLatch is in early access and has no security certification yet; this page says what is in place today and what is not.
Where your data is
- In the EU. The service runs on servers in the European Union; today that is Frankfurt, Germany.
- Encrypted on the way. Every connection to ColdLatch uses HTTPS. In a customer installation loggers connect over TLS, each with its own certificate, and may publish only their own readings.
- Secrets encrypted at rest. The passwords and keys you enter for SAP, email, Slack, Teams and webhooks are stored encrypted and are never shown again.
- No trackers. This website sets no cookies and loads nothing from third parties.
Who can see and do what
- Your company only. Every record belongs to one company, and every request is limited to the company of the person signed in. Another company's records answer "not found".
- Named users with roles. Each person has their own login and one of three roles: viewer, QA or administrator. Only QA and administrators can decide; only administrators change settings and users.
- Passwords. Stored only as salted argon2id hashes. Sign-in attempts are rate-limited. A user can change their own password, which signs their other devices out.
- Sessions. Short-lived, renewed through a cookie the page's scripts cannot read. A stolen session token that is used twice ends every session of that user.
Signed decisions
Approving or rejecting a batch block, retrying one, resolving an alert and changing how alerts are handled each require the user to type their own password again and give a reason. The signature records who, when, why and for which record, and is saved together with the change or not at all. A decision ColdLatch takes by itself in automatic mode is recorded as the system's, never as a person's.
The audit trail
- Everything is recorded: who did what, when, and the record before and after.
- Nothing can be edited or deleted. The database itself refuses changes to audit entries.
- Tampering is detectable. Each entry carries a hash of its content and of the entry before it. An administrator can verify the whole chain with one button, and the log exports with its hashes so it can be re-checked outside ColdLatch.
- One excursion, one record. Each alert produces a PDF report with the readings, the batches, the signed decisions and the audit entries. See a sample report (PDF).
Connections to your systems
- SAP. ColdLatch uses the standard S/4HANA OData APIs with a technical user you create and can restrict. It reads stock for a storage location and posts a transfer to blocked stock; it does nothing else in SAP.
- Outbound addresses are restricted. ColdLatch only calls public HTTPS addresses you configure, never addresses inside its own network, and does not follow redirects.
- Webhooks are signed. Each message carries an HMAC-SHA256 signature made with a secret only you and ColdLatch know. The webhook guide shows how to check it.
Validation support
You validate ColdLatch for your own regulated use; we make that cheaper. On request you get:
- a numbered list of what ColdLatch is required to do, each requirement traced to the automated tests that prove it;
- the test results for the exact release you run;
- an installation and operation checklist to run with us on your environment, with your loggers and your SAP test system.
What is not in place yet
ColdLatch is in early access. We would rather you read this here than find it out later:
- No certification. ColdLatch has no ISO 27001 or SOC 2 certification, and no independent penetration test has been done.
- No formal assessment against EU GMP Annex 11 or 21 CFR Part 11. The signatures and the audit trail were built with those in mind, but nobody qualified has assessed them. We do not claim compliance.
- Single sign-on (Microsoft Entra ID, Google Workspace) is planned, not available.
- One region, one server. There is no second site to fail over to. A customer installation is set up with nightly backups kept off the server, and the expected recovery time is agreed in your contract. The public demo holds only simulated data and is not backed up.
- The legal documents are drafts. The terms, the privacy policy and the data processing agreement are being reviewed.
Reporting a security problem
If you find a weakness in ColdLatch, write to hello@coldlatch.com with what you found and how to reproduce it. We aim to answer within two working days and will not take action against anyone who reports in good faith.