Where the data lives
EU-hosted, Postgres-native, encrypted in transit and at rest.
Every engagement is stored in a Postgres database hosted in the European Union. Traffic between your browser and the platform is TLS-only; storage is encrypted at rest. Backups run daily to encrypted object storage inside the same jurisdiction, with an off-site mirror to a second EU region — see the deployment runbook for the retention and restore-drill schedule.
- Primary region: EU (Postgres + application tier)
- TLS-only traffic (HSTS enforced)
- Encryption at rest via provider-managed keys
- Daily backups + quarterly restore drills
Insider information
We do not ask you to trust us with inside information. We produce the record your general counsel has to keep anyway.
Every access to an engagement is written to an immutable record: who, when, what they opened, who granted it and on what basis. You can export it in insider-list format, to the second, at any time, and you can exclude named individuals from access — including ours.
- Immutable access record — who, when, what, granted by whom, on what basis
- Export in insider-list format, timestamped to the second
- You can exclude named individuals from access, including Cuddly's founders
- The access record survives content deletion, because the insider-list obligation outlives the data
Cuddly produces documentation. Responsibility for compliance with market-abuse regulation remains with the issuer. We do not make you compliant.
How a survey reaches the target
Three modes, and the middle one is enforced in code.
What a respondent sees depends on where the deal is. Before an LOI there is no employee contact at all. During diligence, with the target's consent, the survey carries no acquirer brand and no transaction vocabulary. After announcement it can say what it is.
What the respondent sees at each stage.| Stage | Employee access | What the respondent sees |
|---|
| Before the LOI | None | — |
|---|
| Diligence, with the target's consent | Yes | A standard organisational survey. No acquirer brand, no reference to a transaction. |
|---|
| After announcement | Yes | An integration survey. |
|---|
The middle mode is a technical block, not a guideline. A survey does not publish if it contains the acquirer's brand or transaction vocabulary.
Who we are
On Cuddly's side, the insider list has at most two names — and you know both.
Cuddly is operated by two people. There is no support tier, no offshore operations team and no third party with standing access to an engagement. The size of an insider list is a risk measure in its own right, and this is the smallest it can be. The counterweight to key-person concentration is written process and full data export at any time, without a request procedure.
Respondent protection
A response is not attributable to a person.
Responses are not attributable to an individual. No result is shown for a group of fewer than five, in any filtered view. Identifying details in free text are hidden by default.
Who can see it
Role-aware permissions per engagement — including us.
Access to an engagement is decided by that engagement's member roster, not by which company an account belongs to. Takko Advisory staff have no read access to your engagement unless you invite them. The superadmin role — used for support and platform operations — is restricted to @takkoadvisory.com email domains; every access it performs is written to an audit event you can query at any time.
- Six engagement roles: lead_advisor · analyst · orchestrator · deal_sponsor · integration_lead · hr_lead
- Only the roles you invite see the engagement
- Superadmin restricted to Takko domain; all access audited
- Audit log visible to you — filter by actor, date and event type
Getting it back — and deleting it
Full export any time. GDPR erasure on request.
Your canvas, friction register, evidence and reports are exportable as JSON (canvas) and PDF (memos + packs) at any point from inside the platform. On subscription end nothing is deleted — the engagement drops to read-only until you decide. If you invoke your right to erasure, the request is processed within the statutory window and completion is confirmed via the audit trail.
- Export canvas + config as JSON from every engagement
- Export the Culture Risk Memo as a branded PDF
- Read-only on subscription expiry — nothing is deleted
- GDPR Article 17 erasure endpoint — request via legal@thecuddly.app
What we don't yet have
Honest gap section.
Cuddly is a young platform. Some certifications and controls typical for enterprise SaaS are not yet in place; we are open about it rather than smooth over. When the below become true, this section shrinks.
- SOC 2 Type II — not yet in scope; a Type I is on the FY-26 roadmap
- ISO/IEC 27001 certification is in progress for Takko Technology Oy, scoped to the development, maintenance and support of the platform. No certificate has been issued yet.
- SSO (SAML / OIDC) — Enterprise plan feature; wiring live for Google + Microsoft Entra pending OAuth-app registration
- Bug-bounty programme — not yet launched