How the evidence is kept.
Compliance proof you can’t defend is worse than none.
No certification is claimed on this page. What follows is what the code does and where the data sits.
The result: Clause50 reads your systems and never writes back, and a finalised artifact can be checked by anyone after it leaves Clause50 — without an account.
EU-region hosting covers the application, database, object storage and email. Edge and log processing can run outside the EU — see the subprocessor list.
What each measure protects against.
These measures make a change detectable and a mistake contained; none of them makes an attack impossible.
Who can reach what.
Passwordless sign-in
A one-time link sent to your email address. There is no password to leak, reuse or reset.
Two roles, enforced by the server
Members do the work. Only an owner can change the plan, export the whole account, retract evidence (a new entry; the original stays), create an ingest key or change the team — a member is refused by the server, not shown a hidden button.
Client access for agencies
An agency member can be given every client organisation, or only the ones you select.
Removing someone
Takes effect within five minutes. Their record stays, so the activity log still names who did what.
In transit
HTTPS only. Browsers are told never to fall back to plain HTTP (HSTS).
At rest
Connector credentials are encrypted by our own code. Everything else — records, uploaded files, documents — relies on our hosting providers' storage encryption, not an additional layer of ours.
Connectors only read.
Our connector code sends read requests and nothing else. What the credential you hand us can do depends on the provider:
s3:ListBucket and s3:GetObject on one bucket or prefix — nothing else.Revoke a credential at your provider and the connector stops. Nothing to install on client sites, and nothing of ours in the critical path. Connector setup →
Verify it yourself.
Every finalised pack carries an Ed25519-signed manifest over the whole bundle. Upload its manifest-bundle.json at /verify: the checks run in your browser against our published key — no account, and the pack is never uploaded.
It proves the bundle is byte-for-byte what Clause50 signed, and when. It does not prove the evidence is true or the system compliant.
- Manifest found
- Key in registry
- Signature valid
- Markdown matches
- DOCX matches
- PDF matches
- Specimen claim agrees with key
No pack of your own yet? Try it with the specimen pack (ZIP).
What Clause50 does not do.
- Write to your systems. Connectors only read.
- Sit in your live traffic, or on your site. Nothing to install; the optional ingest API is called by your code, when you choose.
- Edit recorded evidence. A correction is a new entry that retracts the old one; the original stays. Erasing a whole account at your request, under GDPR, is a separate procedure.
- Use a model to write your documents. Generation is deterministic: rendering the final document makes no model calls — asserted by a test.
- Make an AI system compliant, or replace your QMS, conformity assessment or counsel. Where Clause50 stops
Security and legal documents.
Data Processing AgreementSubprocessorsPrivacy
Maintained rules: the rule pack is versioned and cited to the article text. When it is updated, every recorded system is re-scored against it and any new gap is flagged.
Security questionnaire, or a concern to report: admin@clause50.com