Invitation-only authenticated use
Passwordless Kinde authentication and authenticated backend requests.
This summary supports customer due diligence for the current ClauseCast service. It is intentionally explicit about both implemented controls and material limitations.
Contractual security obligations remain set out in Schedule 2 of the Terms. This page is a readable summary, not a replacement for those terms.
Passwordless Kinde authentication and authenticated backend requests.
Cloud Run and Firestore are configured in europe-west2; Kinde is configured in its UK—London region.
Uploaded documents and case bodies are processed without deliberate persistence to Firestore.
The service is not currently offered as a zero-retention architecture.
These controls are proportionate to the current private service and should be read together with the Terms, Privacy Notice and subprocessor disclosures.
These items should form part of any customer’s procurement and information-security assessment.
Gemini project logging is enabled for seven days and ClauseCast has not obtained Gemini zero-data-retention approval.
ClauseCast does not claim that Gemini processing, provider support or all security operations are confined to the UK.
ClauseCast does not currently claim an external information-security certification or independent penetration-test assurance.
Unless an organisation’s authorised compliance or information-security function has approved identifiable use, the current service should be used with anonymised or appropriately pseudonymised commercial case material.