CLARA · Security & Trust

Evidence-scoped, EU-resident by design.

What is implemented today, verifiable in the product. No aspirations. Legal pages (Impressum, Datenschutzerklärung, AGB) follow the legal review; until then, request our DPA at hello@odradekai.com.

Hosting & data residency

  • The CLARA API and application data run on EU infrastructure: a dedicated server in Germany (Hetzner) and an EU-region Postgres (Supabase).
  • The marketing site and dashboard front-end are served via Vercel's CDN; customer signal data is processed by the EU-hosted API, not the CDN.
  • Self-hosting is supported: the API is a standard Docker deployment, and the AI endpoint is workspace-configurable to EU-hosted or fully local models.

Security measures

  • TLS everywhere with HSTS, plus strict security headers on every web and API response.
  • Tenant data is isolated at the database row level. Access control is enforced on the server, by role.
  • Webhook ingestion requires HMAC-SHA256 signatures; API keys are stored as hashes and shown exactly once.
  • Approvals record the verified signer from the login token. A request cannot claim someone else's identity.
  • Audit records are append-only. Evidence packs carry a content hash, so what was approved stays verifiable.

Data subject rights & governance

  • GDPR Art. 17 (erasure) and Art. 20 (export) are product endpoints, not ticket queues.
  • Works-council mode (§87 BetrVG): person-level fields become role labels below admin. No per-employee metric can be derived.
  • EU AI Act Art. 50: non-human-reviewed outbound text carries an automatic AI disclosure; human-approved content records its reviewer.
  • A live model card shows the configured model and its measured accuracy per language, with denominators and dataset date.

AI transparency

  • Provider-agnostic: any OpenAI-compatible endpoint, including EU-hosted and self-hosted local models. No fine-tuning on customer data.
  • Every output carries a model score (labeled as the heuristic it is), evidence links and stated limitations. Thin evidence produces a refusal, not a guess.
  • Outcome readouts are graded A–E by measurement design. Manual entries are labeled as such and never mixed with instrumented measurements.

Certifications & roadmap

  • ISO 27001: roadmapped. DACH shortlists filter on it; pursued as revenue and PII volume grow.
  • BSI C5 (Type 1 → Type 2): sequenced after ISO 27001; doubles as NIS2/DORA supply-chain evidence.
  • DORA ICT-annex and NIS2 supply-chain documentation are prepared for regulated pilots; a signed DPA (AVV) is available on request.

Questions, security reports or DPA requests: hello@odradekai.com

Security & Trust · CLARA