clearlea.se
DE Log in Talk to HieronymusCall
Trust Center

Security, operations and AI principles. In one place.

For procurement, IT security, data protection and audit: how we protect your data, where we process it and what our AI may do. You get the documents on request.

We take your data, your leases and your sovereignty seriously.

Scratch off the fields with your mouse.
  • Data and AI processing in Germany
  • ISO 27001-certified data centres, our own certification in preparation
  • A dedicated instance per customer
  • No AI training on your data
  • Bring your own keys (BYOK) and your own language model
  • Agents with their own permissions, never with user permissions
  • Logs to your monitoring via OpenTelemetry, sign-in via SSO
  • DPA under Art. 28 GDPR, TOMs on request
  • Audit trail for users, AI and systems
GDPRGDPR-compliant. You get the DPA, TOMs and deletion policy with the documents.
Operations

Four deployment models. You choose how much control you keep.

  1. Managed CloudA dedicated instance per customer, hosted in Germany in ISO 27001-certified data centres. Separate hardware, no shared database. On request, entirely without US providers, including for AI.
  2. Private CloudIn your cloud environment, run by your IT. Documented and enterprise-ready. You choose the cloud and the language model.
  3. On-premisesOn your own servers, under your security policies. On request with your own language model.
  4. Air-gappedCan run fully isolated, with no outside connection. The models run in your environment.
From left to right: more control in your hands. Every tier with client separation inside the instance. Installed in hours to a few days with proven deployment scripts.
AI principles

What our AI may do. And what it may never do.

Six principles for how we use AI in clearlea.se. They apply to every feature, every workflow and every agent.

01A human decidesAI prepares, a named person is accountable for every step that counts.
02Everything is backed by evidenceEvery value and every answer points to the document, page and section.
03Rules rank above the modelThresholds and permissions are anchored in code. AI never overrides them.
04Honest about uncertaintyThe QA index flags uncertain values instead of overwriting them.
05Short steps, not long chainsEvery step has its own checkpoint. That keeps quality intact across the whole process.
06Your data stays yoursProcessing in Germany or in your environment. No training on your data.
The AI may
  • Read and classify documents, and suggest values
  • Flag deviations and explain why
  • Prepare drafts
  • Accept values above your QA threshold
The AI may never
  • Act without permission
  • Override rules, thresholds or approvals
  • Change closed cases
  • Be trained on your data
Guarantees

9 built-in guarantees for every automation.

Fixed in code, not in the prompt. That is why even agents can work under strict control, where auditors look closely.

Why it matters
40%+of agentic AI projects will be cancelled by the end of 2027, partly because of inadequate risk controls.Source: Gartner, June 2025
Prompt ≠ ruleAI agents show little awareness of confidentiality on their own. Instructions in the prompt help only to a limited extent and cost performance.Source: Salesforce AI Research, CRMArena-Pro (2025)
1 instruction ignoredIn July 2025, an AI coding agent deleted a production database, even though changes without approval were explicitly forbidden. Imagine an agent sending termination notices across your entire portfolio.Source: eWeek, 22/07/2025
A model can skip anything that lives only in the prompt. That is why clearlea.se puts the rules in code:
  1. 1No change without approvalEvery permission is granted explicitly. What is not allowed does not happen.
  2. 2No action runs twiceA payment, a letter, a handover: exactly once, even if a system stalls.
  3. 3No decision on outdated dataIf the state has changed in the meantime, the workflow checks again instead of deciding on old data.
  4. 4Closed cases stay unchangedWhat is done stays documented exactly as it was decided.
  5. 5Complete audit trailWho, when, why: for people, AI and systems alike.
  6. 6Strict client separation, least privilegeEveryone sees only what they are allowed to see. Clients stay separate.
  7. 7GDPR deletion without losing the audit trailYou can delete personal data. The evidence remains.
  8. 8No faulty workflow goes liveEvery new version is reviewed, tested and approved before release.
  9. 9AI never overrides the rulesRules and thresholds sit above every model, not in the prompt.
Documents

Documents for your review.

We send you the documents after a quick exchange, under NDA if you wish.

  • Technical and organisational measures (TOMs)Access control, encryption, backup, contingency planRequest
  • Data processing agreement (DPA)Under Art. 28 GDPR, as a template for your reviewRequest
  • Architecture overviewComponents, data flows and instance separation, at overview levelRequest
  • Security conceptRoles, permissions, logging and deletion policyRequest
  • Deployment models and installationPrivate cloud, on-premises and isolated operationRequest
  • Sub-processorsData centres and AI inference, each with its locationRequest
  • ISO 27001 certificate of the data centreCertificate of our hosting partner in GermanyRequest
  • AI policyHow we use, review and limit AIRequest
FAQ

The questions procurement and IT security ask.

Where is our data stored and processed?
In data centres in Germany or in your own environment. This also applies to AI processing.
Can it run entirely without US providers, with the CLOUD Act in mind?
Yes. AI processing can run on GPU servers in Germany, or you connect your own language model. On-premises and air-gapped, everything stays in your environment anyway.
Do you train your AI on our data?
No. Neither we nor any model provider uses your data for training.
Who has access to our data?
Only authorised users. Least privilege, strict client separation and an audit trail for every access.
Are you ISO 27001 certified?
We run clearlea.se in ISO 27001-certified data centres. Our own certification is in preparation.
How does GDPR deletion work?
You can delete personal data without losing the audit trail.
Do you support SSO?
Yes. Sign-in via SSO, with freely configurable roles and permissions.
Can we use our own keys and our own model?
Yes. You can encrypt data with your own keys, connected to your key vault. Then not even we have access. And you can connect your own language model.
What permissions do AI agents work with?
Their own. Every workflow step and every agent gets its own permissions and never runs with a user's permissions.
Can we monitor everything centrally?
Yes. You can stream logs and telemetry to your SIEM or monitoring via OpenTelemetry.
Hieronymus Deutsch, co-founder and CEO of clearlea.se
Trust Center

Security questions? Ask us directly.

Talk to Hieronymus Deutsch, co-founder and CEO. For the technical review, Fabian Laußmann, CTO, is happy to join.

Security call with Fabian Laußmann, CTO → From €9.49 per site per month, volume discounts available. Unlimited users, AI usage included.