CLARA · Security & Trust
Evidence-scoped, EU-resident by design.
What is implemented today, verifiable in the product. No aspirations. Legal pages (Impressum, Datenschutzerklärung, AGB) follow the legal review; until then, request our DPA at hello@odradekai.com.
Hosting & data residency
- The CLARA API and application data run on EU infrastructure: a dedicated server in Germany (Hetzner) and an EU-region Postgres (Supabase).
- The marketing site and dashboard front-end are served via Vercel's CDN; customer signal data is processed by the EU-hosted API, not the CDN.
- Self-hosting is supported: the API is a standard Docker deployment, and the AI endpoint is workspace-configurable to EU-hosted or fully local models.
Security measures
- TLS everywhere with HSTS, plus strict security headers on every web and API response.
- Tenant data is isolated at the database row level. Access control is enforced on the server, by role.
- Webhook ingestion requires HMAC-SHA256 signatures; API keys are stored as hashes and shown exactly once.
- Approvals record the verified signer from the login token. A request cannot claim someone else's identity.
- Audit records are append-only. Evidence packs carry a content hash, so what was approved stays verifiable.
Data subject rights & governance
- GDPR Art. 17 (erasure) and Art. 20 (export) are product endpoints, not ticket queues.
- Works-council mode (§87 BetrVG): person-level fields become role labels below admin. No per-employee metric can be derived.
- EU AI Act Art. 50: non-human-reviewed outbound text carries an automatic AI disclosure; human-approved content records its reviewer.
- A live model card shows the configured model and its measured accuracy per language, with denominators and dataset date.
AI transparency
- Provider-agnostic: any OpenAI-compatible endpoint, including EU-hosted and self-hosted local models. No fine-tuning on customer data.
- Every output carries a model score (labeled as the heuristic it is), evidence links and stated limitations. Thin evidence produces a refusal, not a guess.
- Outcome readouts are graded A–E by measurement design. Manual entries are labeled as such and never mixed with instrumented measurements.
Certifications & roadmap
- ISO 27001: roadmapped. DACH shortlists filter on it; pursued as revenue and PII volume grow.
- BSI C5 (Type 1 → Type 2): sequenced after ISO 27001; doubles as NIS2/DORA supply-chain evidence.
- DORA ICT-annex and NIS2 supply-chain documentation are prepared for regulated pilots; a signed DPA (AVV) is available on request.
Questions, security reports or DPA requests: hello@odradekai.com