Skip to content

CRCX is in its founding stage. Continuous proof for identity risk is live today.

We built what we could not find.

Cybersecurity and compliance have been treated for too long as technical problems. They are business problems. They affect continuity, trust, growth, and survival.

What CRCX is

Continuous, verifiable proof of identity risk.

CRCX covers people, machines, and the access paths between them, and it runs entirely on autonomous European infrastructure. So the organisations we serve can stand in front of insurers, regulators, auditors, and partners with proof, on demand.

CRCX proves one thing completely: who and what can reach your critical systems, and whether that access is safe. Not the whole cloud. Not the full weight of every compliance framework. One domain, verified to the bottom.

The scope is narrow on purpose. Narrow scope is what makes the proof complete rather than approximate, and it puts CRCX where the large horizontal platforms are structurally weak rather than competing with them where they are strong.

What makes it work

Two capabilities, both built in house, neither replaceable.

A graph engine models identities, assets, and the access relationships between them as nodes and edges. It then computes what a flat checklist never can: the chains, the blast radius of a compromised account, the paths by which access quietly escalates.

Sovereign infrastructure is the second. It is a structural barrier rather than a marketing line. A US headquartered competitor cannot copy it without rebuilding in Europe from the ground up, and sophisticated European clients in regulated sectors will not let a US hosted platform collect their evidence regardless of where the data sits.

Everything else can be deferred, outsourced, or swapped. These two cannot.

Capability 01

The intelligence engine

Identities, assets, and access relationships as nodes and edges. It computes the chains, the blast radius, and the paths by which access escalates.

Carries

  • Continuous Proof
  • Identity Chain
  • Insurable by Evidence

Capability 02

Sovereign infrastructure

EU BOUNDARY

A structural barrier, not a marketing line. A US headquartered competitor cannot copy it without rebuilding in Europe from the ground up.

Excludes

  • No US cloud provider
  • No sub processor outside the EU
  • No CLOUD Act exposure
Due Diligence Readyrests on both at once. The engine produces the proof. The sovereign infrastructure makes it acceptable to a European party.

Who it serves

One verified data layer. Many parties who trust it.

The scope is narrow. The audience is not, and that is the point of it. Several seats sit at the table: the insurer, the CISO, the CFO, the CIO, partners, and companies going through acquisition or due diligence. Not all of them buy. All of them receive the proof.

Today the client pays. European FinTech scale ups first, then MedTech and HealthTech SaaS. They are cloud native, under DORA and NIS2 pressure, and they decide quickly. They buy insurability and due diligence readiness.

The second paying side is where we are going, not where we are. Insurers buy verified risk data to underwrite more accurately, replacing the annual questionnaire with a continuous signal. That marketplace is not live, and we say so plainly.

Receives the proof

  • CISO
  • CFO
  • CIO
  • Auditor
  • Acquirer
  • Partner
  • Board
Pays today

The client

European FinTech scale ups first, then MedTech and HealthTech SaaS. Buys insurability and due diligence readiness.

Subscription

CRCX

One verified data layer

Building toward

The insurer

Buys verified risk data to underwrite more accurately, replacing the annual questionnaire with a continuous signal. The marketplace is not live.

Licence or per introduction

The route inCyber insurance brokers and MGAs. A client who arrives with a Passport places faster, so the broker wins too.

The belief

Business first. Security always.

CRCX was founded on one belief: business and cybersecurity cannot be separated. We do not just advise. We build, operate, and prove.

Practitioners, not a vendor

Authority earned from doing the work.

The people behind CRCX have implemented compliance programs, managed audits, responded to incidents, and sat in the boardrooms where security decisions get made or avoided. That experience is the foundation of everything the platform does. We work as an entrepreneurial colleague, not a distant supplier.

Why identity, and why now

The one domain that matters most.

Most breaches happen in the access paths between identities, and that is where conventional tooling stops looking. European regulation is raising the bar under NIS2, DORA, and GDPR, and insurers now demand proof before they cover a risk. CRCX proves the one domain that matters most, on infrastructure Europe can trust.

European pressureIdentity and access scope
  • NIS2

    Access governance and accountability for essential entities

  • DORA

    Article 9 safeguards over ICT access, tested and evidenced

  • GDPR

    Demonstrable control over who can reach personal data

Insurers now ask for the same proof

Where CRCX stands today

We say where we stand, and where we are going.

We are in our founding stage, and we say so plainly. Continuous proof for identity risk is live now. The insurance marketplace and full infrastructure sovereignty are the direction of travel, built in sequence and claimed only when they are real. You always see where we stand, and where we are headed. We do not sell a stage. We happen to be in one.

StatusFounding stage · 2026-07
Live now
  • Continuous proof for identity risk
Building toward
  • The insurance marketplace
  • Full infrastructure sovereignty
Built in sequence · Claimed only when real

Start with a conversation.

See it in action, or tell us the real situation, not the official status.