Deadline

Nov 2026: DoD CMMC L2 enforcement begins for new prime contracts. Most DIB firms aren't ready. See your gap →

Privacy Policy

Last updated: June 13, 2026

Cincra is not a C3PAO. This platform automates CMMC readiness, evidence collection, and audit preparation. It does not issue CMMC certifications and does not bind any C3PAO assessment outcome. Attestations generated here reflect the authoring auditor's professional opinion only.

1. What we collect

Account data (email, name, organization), assessment responses, uploaded evidence files, and audit-log activity required to operate the platform.

2. How we use it

Solely to deliver CMMC readiness automation, generate deliverables you request, and produce tamper-evident audit logs scoped to your organization.

3. Storage and retention

Customer content is stored in U.S.-region infrastructure. Cincra is a pilot environment and is not currently authorized for actual CUI. Do not upload real Controlled Unclassified Information. After cancellation, compliance artifacts remain exportable for 30 days; after that the data is deleted and audit logs are retained per our retention policy.

4. Sharing

Auditor sub-processors only receive scope you explicitly grant via time-boxed engagement tokens. We never sell personal data.

5. Subprocessors

The third-party services that process customer data on Cincra's behalf:

SubprocessorPurposeRegionData categoryStatus
Supabase (Postgres, Auth)Primary application database (Postgres) and authentication. Object storage lives in Backblaze B2, not Supabase Storage.AWS us-east-1Account data, assessment responses, evidence metadata, encrypted evidence filesactive
Cloudflare (Workers, DNS)Application hosting on Cloudflare Workers, edge routing, DDoS protection, and DNS for cincra.com and notify.cincra.com.Global edgeRequest metadata, IP addresses (transient)active
Backblaze B2 (object storage)Private-bucket object storage for evidence files, generated SSP/POA&M exports, and policy documents. Server-proxied uploads/downloads; SHA-256 integrity hashes stored alongside.United StatesEvidence files, exports, policy documentsactive
Stripe (payments)Subscription billing, invoicing, and payment-method storage.United StatesBilling contact, payment method tokens (PCI-handled by Stripe)active
Resend (via Lovable Emails on notify.cincra.com)Transactional email delivery for invites, POA&M assignments, and auditor magic links.United StatesRecipient email address, subject line, rendered HTML bodyactive
Google (OAuth identity provider, optional)Optional sign-in via Google. Only used when a user chooses Sign in with Google.GlobalEmail, full name, profile photo URL (from Google OIDC claims)active
AWS GovCloud (US) (planned)Planned destination for FedRAMP Moderate workloads handling CUI. Not in use today.AWS GovCloud (US-West)CUI assessment data, evidence files (when migrated)planned

6. Your rights

Email privacy@cincra.com to access, export, or delete your data.

7. Contact

Cincra · privacy@cincra.com