Skip to content
Applications are open for Crado’s next pilot cohort.Next pilot cohort now open.Join the Waitlist
Crado
Trust Center

Built for regulated engineering teams.

Engineering decisions affect certification, safety and product releases. Crado is designed so every verification workflow is explainable, traceable and under your control.

Data ownership

Your engineering data stays yours.

Crado is built so the data that flows through it remains under your control, not ours.

You own your data
Customer owns all uploaded engineering documents and evidence.
You control access
Access is governed by the roles and permissions you configure.
You can delete
Request deletion of customer data, subject to your agreement and law.
You can export
Decision records and evidence can be exported for your own systems.
You control retention
Retention is governed by your deployment and agreement.
How AI is used

AI reads. Deterministic systems decide.

AI helps make sense of engineering documents. The regulatory conclusions come from a deterministic engine, so the result is explainable rather than generated freely.

AI
Reads
Structures
Suggests
Deterministic engine
Verifies
Links evidence
Applies rules
Produces explainable output
Deployment options

Deploy where your data needs to live.

Crado is designed to meet teams where their security boundary is. Specific options are confirmed as part of an enterprise deployment.

Cloud
Teams that want the fastest path to start.
Data location
Managed cloud, in agreed regions.
Internet access
Connected.
Typical customer
Early pilots and smaller teams.
Private cloud
Teams with their own cloud accounts.
Data location
Your private cloud environment.
Internet access
Connected, within your boundary.
Typical customer
Scale-ups with cloud infrastructure.
On-premise
Teams that keep data inside their network.
Data location
Your own infrastructure.
Internet access
Within your network.
Typical customer
Regulated hardware organisations.
Air-gapped
Teams with the strictest isolation needs.
Data location
Isolated environment, no external egress.
Internet access
None.
Typical customer
Defence, aerospace and classified programs.

Available upon enterprise deployment. Supports private infrastructure where applicable.

Security principles

Principles we design around.

We describe how the platform is designed rather than claiming certifications. These are the principles we build toward.

Least privilege
Access is scoped to what each role needs.
Role-based access
Permissions are assigned by role, not by exception.
Audit logging
Actions within the platform are recorded.
Encrypted communication
Data is encrypted in transit.
Secure authentication
Access requires authenticated, authorised identities.
Versioned records
Decisions and evidence are versioned over time.
Immutable audit history
The audit trail is designed to be append-only.
Engineering traceability
Every decision links back to its sources.
Data handling

How data moves through Crado.

Uploaded engineering documents are processed only for the workflows you request.

Customer uploads evidence
Requirements, specs, test reports and engineering changes.
Processing
Documents are processed only for the workflows you request.
Knowledge graph
Inputs are structured into linked requirements, clauses and evidence.
Verification
A deterministic engine applies rules against the structured data.
Decision record
An explainable record is produced, referencing its sources.
Customer export
You can export records and evidence for your own systems.
Engineering explainability

Every decision traces back to its source.

Nothing is a black box. Each recorded decision links through the chain that produced it.

Hover or focus a step to see how each decision is linked back to its source.
Responsible AI

Evidence first, not confident guesses.

We use AI carefully, with the limitations of language models in mind.

Model limitations
AI is used for reading and structuring, not for final regulatory conclusions.
Human review
Outputs are advisory and meant to be reviewed by qualified engineers.
Evidence-first
Conclusions reference the underlying requirements, clauses and artefacts.
Source traceability
Each result can be traced back to the inputs that produced it.
Versioned outputs
Results are versioned so changes over time are visible.
Confidence reporting
Where confidence is low, the system aims to indicate uncertainty rather than fabricate a conclusion.
Enterprise readiness

What’s available, and what’s on the way.

An honest view of where the platform is today. Specifics are confirmed for your deployment.

Cloud deploymentAvailable
Private cloudEnterprise
On-premiseEnterprise
Air-gappedEnterprise
Single sign-on (SSO)Enterprise
Role-based access (RBAC)Available
API accessRoadmap
Audit logsAvailable
Data exportAvailable
Version historyAvailable
Evidence traceabilityAvailable

Need something not listed here? Contact us.

Frequently asked questions

The questions teams ask first.

No. Crado does not use customer engineering documents to train foundation models. Uploaded artefacts are processed only to perform the verification workflows you request.
Yes. Crado supports on-premise and air-gapped deployments where engineering data remains inside your own infrastructure and is not transmitted to Crado.
You do. As between you and Crado, you retain all rights in the documents and evidence you upload. We process them only to provide the Services to you.
Yes. Decision records and their linked evidence can be exported so they can live in your own certification and quality systems.
Records are versioned and the audit trail is designed to be append-only, so the history of a decision can be reviewed over time.
Crado is built around structured knowledge rather than fixed checklists, so it is designed to be extended with internal standards and proprietary engineering requirements. Availability depends on your deployment, contact us to discuss specifics.
Where confidence is low, the system aims to indicate uncertainty rather than fabricate a conclusion. Regulatory conclusions come from deterministic rules referencing evidence, and outputs are advisory and meant for engineering review.
Security contact

Security questions?

We welcome questions from security and procurement teams, and responsible disclosure of any issues.

Security & responsible disclosure: hello@crado.io
Please include enough detail to reproduce any issue. We aim to acknowledge reports promptly.

Trust should be engineered.

Talk with us about secure deployments for regulated engineering teams.