ColdLatch

Security and compliance

Short answer: your data stays in the EU, each company sees only its own records, every decision is signed with the user's own password, and the audit trail is built so that a changed or missing entry is detected. ColdLatch is in early access and has no security certification yet; this page says what is in place today and what is not.

Where your data is

Who can see and do what

Signed decisions

Approving or rejecting a batch block, retrying one, resolving an alert and changing how alerts are handled each require the user to type their own password again and give a reason. The signature records who, when, why and for which record, and is saved together with the change or not at all. A decision ColdLatch takes by itself in automatic mode is recorded as the system's, never as a person's.

The audit trail

Connections to your systems

Validation support

You validate ColdLatch for your own regulated use; we make that cheaper. On request you get:

What is not in place yet

ColdLatch is in early access. We would rather you read this here than find it out later:

Reporting a security problem

If you find a weakness in ColdLatch, write to hello@coldlatch.com with what you found and how to reproduce it. We aim to answer within two working days and will not take action against anyone who reports in good faith.