The answers your security team will ask for

What you can ask for

  • ISO 27001 certificate. Independently audited and certified on the JAS-ANZ register.
  • Data processing agreement. A standard DPA, ready to sign.
  • Penetration test summary. The most recent report summary, available under NDA.
  • Shared responsibility split. What the platform secures and what stays yours, written down.

Please contact us for more detail.

AI governance

What the AI can reach, and what it cannot

The agent working on one integration cannot see any other. Ask it about another customer's mapping and it has nothing to give you.

The AI proposes, your people review the logic in the visual builder, then it validates against your own message history before it carries a real order.

The engine restricts disk, database and executable access, and applies memory and run-time limits on top. Code the AI writes cannot reach past the integration it was written for.

Non-essential data drops off after 90 days rather than sitting on the platform indefinitely.

Access, control and auditability

Who can reach your data, and what gets recorded

Each integration runs with the minimum permissions it needs to do its job, and nothing more.

Web applications use encrypted communication and APIs use industry-standard authentication. Data exchange runs over SSL/TLS or SSH tunnels, and passwords and access tokens sit encrypted.

Every message and every configuration change lands in a searchable, traceable record with full change history. This is the compliance layer, so when an auditor asks who changed a mapping in March, you have the answer in seconds.

Monitoring watches your application, system and data access logs for unusual behaviour. This is the alerting layer. Alerts fire on failures, delays and endpoint unavailability, so your team hears about a dead endpoint before your trading partner does.

Mappings and message standards version separately. A published version locks while your team builds the next one on a draft, and production reverts to the last working version in one click.

Availability and continuity

What happens when something goes wrong

Search, trace and replay any message, individually or in bulk. A failed live message converts to a draft system test in one click, which turns a bad file into a ten minute fix rather than a re-implementation.

A hosted cloud platform, with redundancy and failover across the engine.

Already moving for ports, transport operators, manufacturers and retailers.

This is the day to day layer. Dashboards show queue depth, throughput, failures and delays. Anything past a threshold sorts to the top.

Certifications and compliance

Independently audited, and verifiable

Independently audited and certified, which gives you an industry-wide baseline rather than our word for it. Check the certificate on the JAS-ANZ register, or ask for the full scope.

Personal data belonging to EU and EEA citizens is handled under GDPR, with a standard data processing agreement ready to sign.

A registered PEPPOL service provider, so your eInvoicing runs on accredited infrastructure rather than a workaround.

Testing runs regularly rather than once a year before an audit, and a summary report is available under NDA.

Hosting and infrastructure

Where the platform runs, and who keeps it running

Platform and vulnerability updates, certificate renewal, key and credential management and connectivity monitoring all sit with us. Self-serve does not mean self-hosted.

The platform runs inside an Amazon Virtual Private Cloud, with subnets segregated by security level and firewalls restricting network access between them. AWS holds SOC 1, SOC 2, SOC 3 and ISO/IEC 27001 for the physical and virtualised environments underneath.

The engine restricts disk, database and executable access, and applies memory and run-time limits on top. Code the AI writes cannot reach past the integration it was written for.

Secure networks with Fortinet and Crowdstrike.

Test and production as standard, kept separate. Larger estates run on dedicated infrastructure rather than shared tenancy.

More than 50 concurrent processing threads, scaling on message load. Work routes to the quietest engine server, so your Monday morning spike gets absorbed rather than banked up.

People, policy and incident response

The part that is not technology

Every staff member is background checked before they start.

Every staff member is trained in handling your data, under policies that are documented rather than assumed.

If something is verified as a breach, you hear about it from us. Our teams are trained to:

  • Respond to alerts promptly
  • Assess the severity and the extent
  • Contain and mitigate where needed
  • Notify you, so your contractual and regulatory obligations are met
  • Preserve evidence for the investigation that follows

Shared responsibility

Where our job ends and yours begins

Your data moves between your systems, the platform and the organisations you trade with. The platform, the hosting, the access controls and the audit trail are ours to secure. Your trading partners stay responsible for security inside their own systems, and your team owns who you grant access to on your side. None of that is left to interpretation. Ask for the shared responsibility split and you get it in writing, so nothing important sits in the gap.

Ownership

Who's behind Crossfire

Sandfield builds and runs Crossfire: privately owned, 25 years in integration, no outside investor steering the roadmap. We own the platform outright, so your bill carries no third party licence and your roadmap does not shift because someone else made an acquisition. The team that builds the engine also runs the managed service on it, so your support question reaches someone who knows the code rather than someone reading a script.

Still have questions? Talk to a Crossfire integration consultant.

© Copyright 2026 Sandfield Associates Limited.

 All Rights Reserved.

 Terms of Use 

 Privacy Policy