Security at Klarefi.
EU data residency. Per-tenant data isolation. No shared-model training on applicant case content.
Three commitments, live today.
EU data residency
Customer case content, primary application storage, document parsing, and AI inference are EU-hosted by default. Limited identity, billing, email, status, and encrypted-backup metadata paths are disclosed on the subprocessor page and fixed in your agreement.
Per-tenant data isolation
Application data is organization-scoped end-to-end, designed so one customer cannot read or query another customer's records.
No shared-model training on case content
Applicant documents, case content, extracted facts, evidence, and personal data are not used to train shared models. Klarefi may use privacy-minimized operational telemetry and feedback to operate, secure, evaluate, and improve the service.
Customer-controlled data plane
As an enterprise option, uploaded documents can be stored in your own cloud bucket and AI inference can run through your own model account with the major cloud providers. Klarefi keeps processing the derived case data as part of the service, and never falls back to its own model account for your cases.
Where we are. What we are working toward.
We are pre-certification. Here is exactly where we are and what we are working toward. Mature security teams in regulated industries tell us they would rather see a clear, honest picture than a glossy badge wall, so that is what this page is.
The commitments above are live today. The work below is in progress. We name certifications on this page when we hold them, not before.
Today
- Structured audit logs
- Per-tenant data isolation
- EU data residency
- Documented controls available on request
Targeted
- Independent certification of our controls
- Alignment with recognized security frameworks
- Customer-facing trust center
Running diligence on Klarefi?
Request our security questionnaire and documented controls. We respond in plain English, with the exact state of every control.
Detailed controls.
Long-form description of the current security posture, architectural safeguards, and operational considerations. Read together with the customer agreement and our data processing agreement.
Our counsel-review DPA template is published at klarefi.com/dpa and is not signable as published. The current subprocessor list is at klarefi.com/subprocessors.
Last updated: July 12, 2026
1. Introduction
This Security Overview / Security Addendum provides a high-level summary of the current security posture, architectural safeguards, and operational considerations for the Services provided by Klarefi ("Klarefi," "we," "us," or "our"). Klarefi is an intake operating system for regulated businesses and may support hosted intake, document upload, operator workspace functions, workflow execution, AI-assisted extraction and routing, audit-relevant logs, and enterprise administrative controls.
This document is intended to support customer diligence, procurement, and security review. It should be read together with the applicable customer agreement, order form, data processing addendum ("DPA") where applicable, and any implementation-specific documentation. Some controls and security characteristics depend on product configuration, deployment model, subscribed plan, or separately documented operational practices.
3. Access Control and Authentication
Klarefi supports authenticated access to operator and administrative surfaces. Enterprise identity features may include organization-linked identity controls and single sign-on ("SSO") where implemented and enabled for the customer's environment.
WorkOS may be used to support identity, login, organization membership, and SSO-related flows. Access to some enterprise features may also depend on subscribed entitlements, commercial packaging, or implementation-specific configuration. This overview does not imply that every identity feature is available in every deployment or plan.
5. Encryption in Transit and at Rest
Klarefi is designed to use industry-standard transport encryption for data transmitted over public networks. Customer data stored by Klarefi-controlled application components or managed infrastructure is intended to be protected at rest where supported by the applicable hosting or storage provider layer and where implemented in the relevant deployment path.
This overview is intentionally high level and does not make specific claims regarding cipher suites, key-management architecture, or provider-specific encryption implementations unless separately documented in customer-facing materials.
6. Application Security Practices
Klarefi seeks to build and operate the service using controlled engineering and application-security practices appropriate for an early-stage SaaS platform serving regulated workflow use cases. Code changes are expected to go through development review and testing processes. Input validation, permission checks, and explicit workflow state handling are used to reduce unsafe or unauthorized actions.
Where implemented, sensitive values such as API secrets or access keys may be hashed, tokenized, scoped, or otherwise handled in a way that avoids unnecessary plaintext persistence. Klarefi favors controlled, typed, gated workflow progression over unconstrained autonomous system behavior.
7. Infrastructure and Hosting Security
Klarefi may rely on managed cloud infrastructure and operational controls for hosting, networking, and administrative access. Specific provider, region, and environment-separation details are governed by the applicable deployment documentation or customer agreement.
8. Logging and Monitoring
Klarefi may maintain authentication and access-related records, workflow status changes and operational events, upload and submission lifecycle events, administrative or configuration changes, usage-related and billing metering events, and service error, monitoring, and troubleshooting records.
These records may be used to support security review, operational support, troubleshooting, service integrity, billing administration, abuse prevention, and audit support. Log content, retention, and availability may vary based on service configuration, dependencies, and the operational purpose of the relevant record type.
9. Auditability and Workflow Traceability
Klarefi is designed for regulated workflows that benefit from traceable progression and reviewable operational history. Hosted intake submissions, uploads, workflow state transitions, and certain operator or administrative actions may be recorded for auditability, support, and workflow troubleshooting.
Workflow execution is designed to preserve an operational trail of how a case moved through intake and review states. Audit-relevant records may include timestamps, event identifiers, state changes, workflow-related context, and other service records useful for review or reconstruction. AI-assisted extraction and workflow support are intended to operate inside this broader traceable system rather than as opaque standalone decisions.
10. Data Segregation and Tenancy Model
Klarefi is designed around organization-scoped application data and access boundaries. The precise tenancy and isolation model may differ by deployment, and customer-facing guarantees are set out in the applicable agreement or architecture documentation.
11. Incident Response
Klarefi maintains internal processes intended to support the identification, triage, investigation, containment, remediation, and follow-up of suspected security incidents affecting Klarefi-controlled systems.
Where required by applicable law or contract, Klarefi expects to notify affected customers in accordance with those obligations. This overview does not establish specific notification timelines unless they are expressly stated in the customer's agreement or other binding documentation.
12. Backup and Recovery
Klarefi's backup service is configured to export Convex and Postgres and copy the complete applicant-document bucket nightly. Payloads are authenticated and encrypted before being written to a separate Railway bucket and off-platform Cloudflare R2, with 30-day retention. The operating target is an RPO of 24 hours or less and an RTO of four hours or less.
Production readiness requires a successful, evidenced restore drill; the presence of backup files alone is not treated as proof of recoverability. Customer-specific recovery commitments remain those in the applicable agreement.
13. Vulnerability Management
Klarefi seeks to identify and address vulnerabilities through routine engineering maintenance, dependency updates, defect remediation, and issue triage. Security issues identified internally, by customers, or by service providers may be prioritized based on severity, exploitability, exposure, and operational impact.
Remediation timing varies based on the nature of the issue and the affected service surface. This overview does not imply a public bug bounty, formal penetration-testing program, or fixed remediation SLA unless separately documented.
14. Subprocessors / Third-Party Providers
Klarefi relies on a small set of third-party providers for hosting, data storage, worker compute, AI inference, identity, billing, and transactional email. The current list, with each provider's purpose and processing location, is published at klarefi.com/subprocessors, where changes are posted first.
Each provider is bound by data protection obligations materially no less protective than our data processing agreement, which also sets out the notice and objection process for subprocessor changes.
15. AI-Assisted Processing Considerations
Klarefi may use AI-assisted methods for extraction, classification, summarization, gap detection, routing support, and workflow assistance. Such outputs may be probabilistic, incomplete, inconsistent, or unsuitable for a particular customer use without review.
AI-assisted functions operate within configured workflows, business rules, review states, and broader operational controls rather than replacing customer governance. Depending on customer configuration and use case, human review may be required before downstream action, escalation, or final decisioning. Customers remain responsible for evaluating whether their workflow design, review thresholds, and overall control environment satisfy applicable legal and regulatory obligations.
16. Customer Configuration Responsibilities
Customers are responsible for selecting what information they request from applicants or end users, configuring workflow rules, review paths, approvals, and escalation logic, assigning appropriate user roles, and removing access promptly when it is no longer needed.
Customers are also responsible for managing SSO and identity-provider settings where applicable, deciding whether human review is required before taking regulated action, and validating downstream integrations, exports, and system-of-record updates. Enterprise authentication and entitlement controls can help support access control, but they do not replace customer-side user administration and governance.
17. Security Contact / Reporting
Security inquiries and vulnerability reports may be sent to [email protected]. Our security.txt is published at /.well-known/security.txt.
18. Important Limitations / No Absolute Guarantees
No internet-connected software or managed service can guarantee absolute security, uninterrupted availability, or error-free automated outputs. Security and control outcomes depend in part on customer configuration, user administration, provider dependencies, workflow design, and operational context.
This overview is provided for general informational purposes and does not amend the customer agreement, DPA, order form, or any other binding commitment. Klarefi does not by this document assume responsibility for legal, underwriting, claims, compliance, medical, or other regulated determinations that remain the responsibility of the customer or its authorized personnel.