ClauseCast
Security & data handling

Current controls, data flows and limitations in one place.

This summary supports customer due diligence for the current ClauseCast service. It is intentionally explicit about both implemented controls and material limitations.

At a glance

Current service posture.

Contractual security obligations remain set out in Schedule 2 of the Terms. This page is a readable summary, not a replacement for those terms.

Access

Invitation-only authenticated use

Passwordless Kinde authentication and authenticated backend requests.

Application region

London configuration

Cloud Run and Firestore are configured in europe-west2; Kinde is configured in its UK—London region.

Case persistence

No deliberate Firestore storage

Uploaded documents and case bodies are processed without deliberate persistence to Firestore.

AI retention

7-day Gemini project logging

The service is not currently offered as a zero-retention architecture.

Technical controls

Controls currently described for the service.

These controls are proportionate to the current private service and should be read together with the Terms, Privacy Notice and subprocessor disclosures.

Identity

Authentication & access

  • Passwordless Kinde authentication
  • JWT issuer, audience and RS256 signature verification
  • Server-side access controls / allowlisting
  • Authenticated account access
Application

Request & upload controls

  • HTTPS/TLS transport
  • Restricted production CORS
  • Input and request validation
  • Rate limiting and upload limits
  • One-time refinement tokens and transactional credit enforcement
Data

Minimised application storage

  • Transient document parsing
  • Case bodies not deliberately written to Firestore
  • Data-minimised application logging
  • Firestore scheduled backups and point-in-time recovery disabled
Important limitations

What ClauseCast does not currently claim.

These items should form part of any customer’s procurement and information-security assessment.

Retention

No zero-data-retention claim

Gemini project logging is enabled for seven days and ClauseCast has not obtained Gemini zero-data-retention approval.

Location

Not all processing is UK-confined

ClauseCast does not claim that Gemini processing, provider support or all security operations are confined to the UK.

Assurance

No external certification claim

ClauseCast does not currently claim an external information-security certification or independent penetration-test assurance.

Recommended use

Minimise live matter data.

Unless an organisation’s authorised compliance or information-security function has approved identifiable use, the current service should be used with anonymised or appropriately pseudonymised commercial case material.

Do not submit unnecessary personal data, privileged communications, raw client matter files or sensitive information without the appropriate documented assessment and authority. Professional users remain responsible for confidentiality, privilege, data-protection and supervision requirements.