Privacy Policy
Last updated: June 13, 2026
Cincra is not a C3PAO. This platform automates CMMC readiness, evidence collection, and audit preparation. It does not issue CMMC certifications and does not bind any C3PAO assessment outcome. Attestations generated here reflect the authoring auditor's professional opinion only.
1. What we collect
Account data (email, name, organization), assessment responses, uploaded evidence files, and audit-log activity required to operate the platform.
2. How we use it
Solely to deliver CMMC readiness automation, generate deliverables you request, and produce tamper-evident audit logs scoped to your organization.
3. Storage and retention
Customer content is stored in U.S.-region infrastructure. Cincra is a pilot environment and is not currently authorized for actual CUI. Do not upload real Controlled Unclassified Information. After cancellation, compliance artifacts remain exportable for 30 days; after that the data is deleted and audit logs are retained per our retention policy.
4. Sharing
Auditor sub-processors only receive scope you explicitly grant via time-boxed engagement tokens. We never sell personal data.
5. Subprocessors
The third-party services that process customer data on Cincra's behalf:
| Subprocessor | Purpose | Region | Data category | Status |
|---|---|---|---|---|
| Supabase (Postgres, Auth) | Primary application database (Postgres) and authentication. Object storage lives in Backblaze B2, not Supabase Storage. | AWS us-east-1 | Account data, assessment responses, evidence metadata, encrypted evidence files | active |
| Cloudflare (Workers, DNS) | Application hosting on Cloudflare Workers, edge routing, DDoS protection, and DNS for cincra.com and notify.cincra.com. | Global edge | Request metadata, IP addresses (transient) | active |
| Backblaze B2 (object storage) | Private-bucket object storage for evidence files, generated SSP/POA&M exports, and policy documents. Server-proxied uploads/downloads; SHA-256 integrity hashes stored alongside. | United States | Evidence files, exports, policy documents | active |
| Stripe (payments) | Subscription billing, invoicing, and payment-method storage. | United States | Billing contact, payment method tokens (PCI-handled by Stripe) | active |
| Resend (via Lovable Emails on notify.cincra.com) | Transactional email delivery for invites, POA&M assignments, and auditor magic links. | United States | Recipient email address, subject line, rendered HTML body | active |
| Google (OAuth identity provider, optional) | Optional sign-in via Google. Only used when a user chooses Sign in with Google. | Global | Email, full name, profile photo URL (from Google OIDC claims) | active |
| AWS GovCloud (US) (planned) | Planned destination for FedRAMP Moderate workloads handling CUI. Not in use today. | AWS GovCloud (US-West) | CUI assessment data, evidence files (when migrated) | planned |
6. Your rights
Email privacy@cincra.com to access, export, or delete your data.
7. Contact
Cincra · privacy@cincra.com