Skip to content

CRCX is in its founding stage. Continuous proof for identity risk is live today.

Identity proof · Live · v0.9

You can always prove you are in control.

Continuous, verified proof of who and what can reach your critical systems. Ready the moment an insurer, an auditor, a customer, or an acquirer asks you to prove it.

Identity chain · SampleVerified · 2026-07-22
An identity graph with one access chain highlightedHuman and machine identities connected by access paths. One chain runs from a human identity through a service account to a critical system, crossing at a marked intersection. The blast radius around the critical system is shown as a soft field.HUMANSERVICE ACCTCRITICAL SYSTEMINTERSECTIONBLAST RADIUS

Identities
1,284
Access paths
4,116
Critical chains
7

Sample estate · Illustrative figures

The problem

The question always comes. The answer is usually a scramble.

When an insurer, a customer, or an acquirer asks you to prove your security, most teams lose weeks to forms, screenshots, and a snapshot that was already stale when they sent it. CRCX makes the proof exist before the question is asked, and keeps it current.

What CRCX is

The identity proof layer for European cyber risk.

CRCX delivers continuous, verifiable proof of identity risk. It covers people, machines, and the access paths between them, and it runs entirely on autonomous European infrastructure.

So you can stand in front of insurers, regulators, auditors, and partners with proof, on demand.

It sits under the question rather than beside it. Your identity systems feed it. Everyone who asks you to prove yourself reads from it.

Out · One signed record

Insurability Passport
CRCX·P·000241 · 2026-07-22

Read by

  • Insurer
  • Auditor
  • Customer
  • Acquirer
  • Board
  • Regulator
Generated on demand

CRCX

The identity proof layer

Chains resolved · Signed · Method v0.9 · EU infrastructure
In · Your identity systemsRead continuously at the source
  • Okta
  • Entra ID
  • AWS IAM
  • GCP IAM
  • Azure AD

What we prove

One domain, verified to the bottom.

CRCX proves one thing completely: who and what can reach your critical systems, and whether that access is safe. The people, the machines, and the access paths between them. Not the whole cloud. Not every framework at once.

The human side is your employees, their roles, their multi factor status, their sessions. The machine side is your API keys, service accounts, and tokens, the non human identities that carry no alarm when they leak. And the chains between them, where a compromised marketing account reaches a production database through a forgotten key. That chain is where most breaches happen, and it is exactly where conventional GRC tooling stops looking.

Identity estateHuman · Machine
  • Employees
  • Roles
  • Multi factor
  • Sessions
  • API keys
  • Service accounts
  • Tokens
  • Workloads
One chain crosses domains · Illustrative

Five things you are actually buying.

  • 01Live

    Continuous Proof


    Live, cryptographically signed evidence drawn straight from your source systems. Not a questionnaire. Not an annual snapshot. The posture of today, provable today.

  • 02Human · Machine

    Identity Chain


    The full scope of who and what can reach critical systems, human and machine, and the access paths between them.

  • 03EU

    European Autonomy


    Every component runs on infrastructure CRCX owns in Europe. No US cloud, no sub processor outside the EU.

  • 04On demand

    Due Diligence Ready


    Proof built to satisfy any party that asks you to prove yourself: an insurer, an acquirer, a supply chain customer, a board, a regulator. Whenever someone says prove it, the proof already exists.

  • 05Commercial

    Insurable by Evidence


    Verified posture translated into commercial standing. The evidence that makes you insurable, ready on demand.

How it works · Connect

Connect once. The proof runs itself.

You connect Okta, Entra ID, or your cloud IAM. CRCX reads your identity and access posture straight from the source. No questionnaires, no manual uploads.

SourcesRead only · Continuous
  • Okta
  • Entra ID
  • AWS IAM
  • GCP IAM
  • Azure AD

CRCX

Graph engine

No questionnaires · No manual uploads

How it works · The engine

The engine maps the chains, not just the checkboxes.

A graph engine models every identity, asset, and access path, human and machine, then computes the chains and the blast radius. It shows how a compromised account actually reaches a critical system. This is the difference between “MFA is on” and “if this account falls, the transaction engine is exposed.”

Access graph · Computed chainsIllustrative
An access graph with one chain and its blast radiusHuman and machine identities connected by access paths. One highlighted chain runs from a marketing account through a forgotten key to a production database. A soft field marks everything that database exposes.MARKETING ACCTFORGOTTEN KEYPRODUCTION DBINTERSECTIONBLAST RADIUS
  • Human identity
  • Machine identity
  • Highlighted chain
  • Blast radius

The bounded control set

Every green light maps to a control someone recognises.

The proof is scoped to a defined, published set of identity and access controls that insurers and regulators both accept: the seven non negotiable IAM hard stops that cyber insurers require, the identity and access domains of ISO 27001 Annex A.5 and A.8, DORA Article 9, SOC 2 CC6.1 through CC6.3, and the relevant NIS2 obligations. The scope is the edge of the promise, and we state it openly.

Control scope9 frameworks · Published
  • IAM.01Multi factor on all human identities
  • IAM.02Privileged access reviewed
  • IAM.03Service account inventory
  • ISO A.5Access control policy
  • ISO A.8Identity management
  • DORA 9ICT access safeguards
  • SOC2 CC6.1Logical access
  • SOC2 CC6.2User provisioning
  • NIS2Access governance
Scope stated openly

The dashboard

One source, in the language of each seat at the table.

The dashboard shows your posture, the chains, and the controls that need attention. The CISO sees risk and remediation. The CFO sees investment and premium impact. The CIO sees architecture and dependencies. You fix what is critical before the proof goes out.

PostureLive · Sample data
  • CISO

    Risk and remediation

  • CFO

    Investment and premium impact

  • CIO

    Architecture and dependencies

  • IAM.01Privileged accessVerified
  • IAM.04Dormant service accountsNeeds attention
  • A.5.15Access control policyVerified
  • DORA.9Access path reviewVerified

The Insurability Passport

The proof you hand over, generated in minutes.

When someone asks you to prove it, you generate a cryptographically signed Insurability Passport. Hand it to the broker, the underwriter, the acquirer, or the auditor. What took weeks of manual forms takes minutes, and the evidence is already verified.

Passport · CRCX-P-000241Signed · Sample
Issued
2026-07-22 · 14:03 UTC
Method
v0.9
Scope
Identity & Access · A.5, A.8
Hash
0x8a3f…c1d2
  • IAM.01Privileged access reviewedVerified
  • IAM.03Multi factor enforcedVerified
  • A.8.2Machine identity inventoryVerified
  • CC6.2Joiner mover leaverVerified
Cryptographically signedSHA 256

Why it pays

It pays for itself every time you have to prove you are in control.

You become insurable and place faster. You pass due diligence without the fire drill. You clear enterprise vendor assessments in days instead of weeks. You stay audit ready year round.

See how insurability works

Sovereign by design

European by architecture, not by label.

Every component runs on infrastructure CRCX owns in Europe, auditable end to end, building toward owned servers in Germany. For an organisation under NIS2, DORA, and GDPR, that is what makes the proof acceptable to a party that will not accept a US hosted answer.

See how we handle trust and sovereignty

Prove it, on demand.

See it in action. Create an account and explore your own preview environment, or talk to us about something concrete.