Information security at Craxel. Last updated: 6 August 2026
Our commitment
Craxel is committed to protecting the confidentiality, integrity and availability of information assets belonging to our organisation, our customers and our partners. Security is fundamental to how we operate, particularly given our focus on defence, government and regulated sectors.
This commitment applies both to how we run our own business and to how the Black Forest platform is engineered, which is built on a zero trust foundation and designed to be secure by design and memory safe.
Certifications and accreditations
Cyber Essentials and Cyber Essentials Plus certification in the United Kingdom.
JOSCAR approved, the Joint Supply Chain Accreditation Register used across the UK aerospace, defence and security sectors.
Our security programme
A risk based approach to information security management, with controls proportionate to the sensitivity of the information involved.
Access controls based on least privilege, with access reviewed and removed promptly when roles change.
Encryption of data in transit and at rest.
Regular security testing and vulnerability assessment, with remediation tracked to closure.
Incident response and business continuity procedures, exercised and reviewed.
Security assessment of suppliers and subcontractors who handle our information or our customers' information.
Security awareness training for all staff, refreshed regularly and reinforced for those in higher risk roles.
Security in the platform
Black Forest applies fine grained access control inside the database engine rather than relying only on controls above it. High Performance Searchable Encryption allows data to be encrypted at the application layer and then searched without the data layer holding the encryption keys, so security is not traded for speed of access. Customers retain ownership of their data, formats, ontologies, queries and access policies.
Reporting a security concern
If you believe you have identified a security vulnerability or have a security concern relating to our website, our products or our business, please report it to info@craxel.com. Please include enough detail for us to reproduce or understand the issue, and do not include classified, export controlled or other sensitive material in your report.
We will acknowledge reports made in good faith and will work with you on responsible disclosure. We ask that you give us reasonable opportunity to investigate and remediate before any public disclosure.
Continuous improvement
We review our security posture regularly through internal review, external assessment and certification audits, and we monitor emerging threats and evolving good practice so that our controls remain appropriate as our business and our products develop.