Trust at Klavius.
Klavius holds the compliance record of regulated fund managers. This page gathers everything about how we protect it — the security architecture, the providers we rely on, and how we handle personal data — in one place, in plain terms.
EU-hosted by design
The application, its database, and uploaded documents are hosted in the EU. The providers that process your content, the AI included, are listed under Subprocessors.
Tenant isolation at the database
Every firm's data is separated at the database layer using PostgreSQL row-level security — not only in application code. Each request runs under a per-tenant database role scoped to that single firm, so a query can only ever reach that firm's own rows. Isolation is enforced by the database itself, and covered by an automated test suite that asserts one tenant can never see another's data.
A tamper-evident audit trail
Every AI analysis and every officer sign-off is written to an append-only log. Database-level controls block any later modification or deletion of those records — including by a database administrator. Each entry also carries a cryptographic integrity signature (HMAC-SHA256), so any change to a stored record is detectable. An evidence dossier is a query, not a fire drill.
Access control and segregation of duties
Access is role-based (administrator, officer, viewer) and enforced on the server, not merely hidden in the interface. Klavius is built on a simple principle: the AI proposes, and a human officer signs. Read-only users cannot approve, override a verdict, or submit a record; sign-offs are attributed to the authenticated user who made them.
Encryption
All traffic is encrypted in transit with TLS. Data is encrypted at rest by our infrastructure providers, both for the database and for document storage.
Authentication
Sign-in is handled by Clerk using signed, short-lived tokens verified on every request. Klavius runs in a restricted-access model: accounts are provisioned for named firms, with no open self-service signup.
AI and subprocessors
To read and draft compliance content, Klavius relies on a small, named set of service providers. We publish exactly who they are, what they process, and where, under Subprocessors. Content sent for AI analysis is not used to train AI models.
Operational security
Secrets live in the deployment environment, never in source control. The service refuses to start if a required security setting is missing, and changes run through automated checks before release.
Certifications
Klavius is not yet SOC 2 or ISO 27001 certified; formal certification is on our roadmap. In the meantime, we're glad to complete your vendor due-diligence questionnaire and walk your team through the controls above.
Reporting a security issue
Found something? Email security@klavius.ai and we'll respond promptly. Responsible disclosure is welcome.
To operate Klavius, we rely on a small number of trusted service providers ("subprocessors") that process data on our behalf. We keep this list current and limit it to what running the platform genuinely requires.
| Subprocessor | Purpose | Data processed | Region |
|---|---|---|---|
| Anthropic | AI reading & drafting (Claude) — the analysis behind Regulatory Watch, risk scoring, and drafting | Compliance content submitted for analysis: uploaded documents, register data, and officer notes | United States |
| Railway | Application hosting & PostgreSQL database | All platform data | European Union |
| Cloudflare R2 | Uploaded-document storage | Files uploaded to the platform | European Union (EU-jurisdiction endpoint) |
| Clerk | Authentication & identity | Account identifiers, email address, and organisation membership | United States |
International transfers
The application, database, and document storage are hosted in the European Union. Two providers — Anthropic and Clerk — process data in the United States; those transfers are governed by the providers' standard data-processing terms, including EU Standard Contractual Clauses. We can share our data-processing terms with clients as part of due diligence.
Changes to this list
We update this page whenever we add, remove, or replace a subprocessor. If you'd like to be notified of changes in advance, tell us at info@klavius.ai.
How Klavius handles personal data, in plain terms. This notice covers the marketing site and the Klavius platform.
1. Who we are
The Klavius platform is operated by [Klavius Entity] ("Klavius", "we"), a company established in Luxembourg.
- Registered office: [address] · Company number: [RCS Luxembourg no.]
- Data-protection contact: [privacy@klavius.ai]
- Lead supervisory authority: [Luxembourg CNPD]
2. What we collect, and why
For firms using the platform, we act as a processor of the compliance content you upload — documents, register data and officer notes — on your instructions. For account administration and the marketing site, we act as a controller of a limited set of data:
- Account & identity — name, work email, organisation and role, to provision and secure access.
- Usage & security logs — to keep the service reliable and auditable.
- Enquiries — what you send us when you request a demo or contact us.
We do not sell personal data, and we do not use your compliance content for advertising.
3. Who we share it with
We rely on a small, named set of service providers ("subprocessors") to run the platform. Exactly who they are, what they process and where is published on our Subprocessors page. Content sent for AI analysis is not used to train AI models.
4. International transfers
The application, database and document storage are hosted in the European Union. Two providers process data in the United States; those transfers are governed by the providers' data-processing terms, including EU Standard Contractual Clauses. See Subprocessors.
5. How long we keep it
Compliance content is retained for as long as your firm's account is active and then handled per your instructions and our retention schedule. Account data is deleted within [X months] of account closure unless a legal obligation requires longer. Our audit records are append-only by design — our retention record explains how erasure requests are honoured against a tamper-evident store.
6. Your rights
Subject to applicable law, you may request access to, correction of, or deletion of your personal data, object to or restrict certain processing, and request portability. Where a firm is the controller of compliance content, we direct such requests to that firm. Contact [privacy@klavius.ai]. You also have the right to lodge a complaint with your supervisory authority.
7. How we protect it
EU hosting, database-enforced tenant isolation, encryption in transit and at rest, role-based access, and a tamper-evident audit trail. The full picture is on our Security page.
8. Cookies
The platform uses only the cookies strictly necessary to keep you signed in securely. Details, and any choices available to you, are on the Cookies page.
9. Changes
We update this notice as the service evolves and will change the date below when we do. Material changes will be communicated to account administrators.
Klavius runs lean on cookies. We use only what is needed to sign you in and keep the session secure — no advertising, and no cross-site tracking of your compliance work.
| Cookie | Set by | Purpose | Type |
|---|---|---|---|
| Session / auth | Clerk (authentication) | Keeps you securely signed in and protects against request forgery | Strictly necessary |
| Preferences | Klavius | Remembers basic interface state so the app behaves consistently | Strictly necessary |
Managing cookies
Because the cookies above are strictly necessary to sign in and operate the platform, disabling them will prevent the service from working. You can clear or block cookies in your browser settings at any time; doing so will sign you out.
Changes
If our cookie use changes, we will update this page and the date below.
Klavius is an AI product, and we're direct about how the AI works, where it sits, and where its limits are. The principle is simple: Klavius proposes, your officer decides.
Klavius proposes, your officer decides
Every analysis Klavius produces — a regulatory-watch impact note, a risk score, a monitoring verdict, a draft report — is a proposal for a qualified officer to review, edit and sign off. The AI never files, approves or submits anything on its own. Read-only users can't approve; a sign-off is attributed to the authenticated officer who made it. Human oversight isn't a policy statement here — it's enforced in the product.
What the AI sees, and what it never does
To read and draft compliance content, Klavius sends the material you submit — documents, register data, officer notes — to one named model provider, Anthropic (Claude). That content is processed to generate the analysis and is not used to train AI models. There is no advertising, no profiling, and no second AI provider quietly in the chain. The full list is on Subprocessors.
Every AI decision is on the record
Each AI call is written to an append-only, signature-chained audit log. You can always answer the auditor's question: what did Klavius say, when, on what basis, and which officer signed it off. More on Security.
Where Klavius sits under the EU AI Act
The AI Act works along a chain of responsibility. Here is where each party stands — and why the design keeps you, the deployer, in control.
Because a qualified officer makes and signs every decision, Klavius is built as a decision-support system with mandatory human oversight — not an autonomous decision-maker — and is not intended to operate as a high-risk AI system. The regulated judgement stays with your firm's officers; Anthropic, upstream, holds its own general-purpose-model duties.