Skip to content
Clause50EU AI Act evidence — starting with Article 50.EU AI Act evidence, starting with Article 50
Security

How the evidence is kept.

Compliance proof you can’t defend is worse than none.

No certification is claimed on this page. What follows is what the code does and where the data sits.

Your systems
Read-only connectors, one direction
A usage report, a repository, an S3 export. Nothing is written back.
EU-region hosting
Application · database · object store
Email too. Edge and log processing can run outside the EU.
Evidence store
Append-only, hash-chained
No update, no delete — enforced in CI. Each item chained to the one before.
Every finalised artifact
Ed25519-signed manifest
/verify
Public verification, no account
Checked in the reader’s browser; the pack is never uploaded.

The result: Clause50 reads your systems and never writes back, and a finalised artifact can be checked by anyone after it leaves Clause50 — without an account.

EU-region hosting covers the application, database, object storage and email. Edge and log processing can run outside the EU — see the subprocessor list.

Threats and measures

What each measure protects against.

A recorded item is edited or deleted laterThere is no update or delete path — a CI test scans the code and every migration. Each item is hash-chained to the one before it.
A pack is altered after it was signedThe Ed25519 signature covers every file in the bundle. Change one byte and verification fails.
The recipient has to take our word for itThey check the pack at /verify, in their own browser, against our published key — no account, and the pack is never uploaded.
One customer's data reaches anotherDatabase access is scoped to your organisation by the application, and a standing test tries to cross between organisations against a real database.
A stored connector credential leaksCredentials are sealed-box encrypted, never logged, and never shown again — not even to our own support tooling.
Someone at Clause50 looks at your accountSupport access is written into your own account's activity log, as an entry you can read and export.

These measures make a change detectable and a mistake contained; none of them makes an attack impossible.

Access

Who can reach what.

Passwordless sign-in

A one-time link sent to your email address. There is no password to leak, reuse or reset.

Two roles, enforced by the server

Members do the work. Only an owner can change the plan, export the whole account, retract evidence (a new entry; the original stays), create an ingest key or change the team — a member is refused by the server, not shown a hidden button.

Client access for agencies

An agency member can be given every client organisation, or only the ones you select.

Removing someone

Takes effect within five minutes. Their record stays, so the activity log still names who did what.

In transit

HTTPS only. Browsers are told never to fall back to plain HTTP (HSTS).

At rest

Connector credentials are encrypted by our own code. Everything else — records, uploaded files, documents — relies on our hosting providers' storage encryption, not an additional layer of ours.

Connectors

Connectors only read.

Our connector code sends read requests and nothing else. What the credential you hand us can do depends on the provider:

GitHubA fine-grained token for one repository, with read-only access to Contents.
S3 log exports3:ListBucket and s3:GetObject on one bucket or prefix — nothing else.
OpenAI · AnthropicTheir usage reports require an Admin key, which can do more than we use it for. We store it sealed-box encrypted and call one read endpoint with it.

Revoke a credential at your provider and the connector stops. Nothing to install on client sites, and nothing of ours in the critical path. Connector setup →

Verification

Verify it yourself.

Every finalised pack carries an Ed25519-signed manifest over the whole bundle. Upload its manifest-bundle.json at /verify: the checks run in your browser against our published key — no account, and the pack is never uploaded.

It proves the bundle is byte-for-byte what Clause50 signed, and when. It does not prove the evidence is true or the system compliant.

Independent verification
/verify · no account needed
✓ Valid — Clause50 specimen document (not evidence)
  • Manifest found
  • Key in registry
  • Signature valid
  • Markdown matches
  • DOCX matches
  • PDF matches
  • Specimen claim agrees with key

No pack of your own yet? Try it with the specimen pack (ZIP).

Boundaries

What Clause50 does not do.

  • Write to your systems. Connectors only read.
  • Sit in your live traffic, or on your site. Nothing to install; the optional ingest API is called by your code, when you choose.
  • Edit recorded evidence. A correction is a new entry that retracts the old one; the original stays. Erasing a whole account at your request, under GDPR, is a separate procedure.
  • Use a model to write your documents. Generation is deterministic: rendering the final document makes no model calls — asserted by a test.
  • Make an AI system compliant, or replace your QMS, conformity assessment or counsel. Where Clause50 stops
Documents

Security and legal documents.

Data Processing AgreementSubprocessorsPrivacy

Maintained rules: the rule pack is versioned and cited to the article text. When it is updated, every recorded system is re-scored against it and any new gap is flagged.

Security questionnaire, or a concern to report: admin@clause50.com