Operations
Four deployment models. You choose how much control you keep.
- Managed CloudA dedicated instance per customer, hosted in Germany in ISO 27001-certified data centres. Separate hardware, no shared database. On request, entirely without US providers, including for AI.
- Private CloudIn your cloud environment, run by your IT. Documented and enterprise-ready. You choose the cloud and the language model.
- On-premisesOn your own servers, under your security policies. On request with your own language model.
- Air-gappedCan run fully isolated, with no outside connection. The models run in your environment.
AI principles
What our AI may do. And what it may never do.
Six principles for how we use AI in clearlea.se. They apply to every feature, every workflow and every agent.
01A human decidesAI prepares, a named person is accountable for every step that counts.
02Everything is backed by evidenceEvery value and every answer points to the document, page and section.
03Rules rank above the modelThresholds and permissions are anchored in code. AI never overrides them.
04Honest about uncertaintyThe QA index flags uncertain values instead of overwriting them.
05Short steps, not long chainsEvery step has its own checkpoint. That keeps quality intact across the whole process.
06Your data stays yoursProcessing in Germany or in your environment. No training on your data.
The AI may
- Read and classify documents, and suggest values
- Flag deviations and explain why
- Prepare drafts
- Accept values above your QA threshold
The AI may never
- Act without permission
- Override rules, thresholds or approvals
- Change closed cases
- Be trained on your data
Guarantees
9 built-in guarantees for every automation.
Fixed in code, not in the prompt. That is why even agents can work under strict control, where auditors look closely.
Why it mattersA model can skip anything that lives only in the prompt. That is why clearlea.se puts the rules in code:
40%+of agentic AI projects will be cancelled by the end of 2027, partly because of inadequate risk controls.Source: Gartner, June 2025
Prompt ≠ ruleAI agents show little awareness of confidentiality on their own. Instructions in the prompt help only to a limited extent and cost performance.Source: Salesforce AI Research, CRMArena-Pro (2025)
1 instruction ignoredIn July 2025, an AI coding agent deleted a production database, even though changes without approval were explicitly forbidden. Imagine an agent sending termination notices across your entire portfolio.Source: eWeek, 22/07/2025
- 1No change without approvalEvery permission is granted explicitly. What is not allowed does not happen.
- 2No action runs twiceA payment, a letter, a handover: exactly once, even if a system stalls.
- 3No decision on outdated dataIf the state has changed in the meantime, the workflow checks again instead of deciding on old data.
- 4Closed cases stay unchangedWhat is done stays documented exactly as it was decided.
- 5Complete audit trailWho, when, why: for people, AI and systems alike.
- 6Strict client separation, least privilegeEveryone sees only what they are allowed to see. Clients stay separate.
- 7GDPR deletion without losing the audit trailYou can delete personal data. The evidence remains.
- 8No faulty workflow goes liveEvery new version is reviewed, tested and approved before release.
- 9AI never overrides the rulesRules and thresholds sit above every model, not in the prompt.
Documents
Documents for your review.
We send you the documents after a quick exchange, under NDA if you wish.
FAQ
The questions procurement and IT security ask.
- Where is our data stored and processed?
- In data centres in Germany or in your own environment. This also applies to AI processing.
- Can it run entirely without US providers, with the CLOUD Act in mind?
- Yes. AI processing can run on GPU servers in Germany, or you connect your own language model. On-premises and air-gapped, everything stays in your environment anyway.
- Do you train your AI on our data?
- No. Neither we nor any model provider uses your data for training.
- Who has access to our data?
- Only authorised users. Least privilege, strict client separation and an audit trail for every access.
- Are you ISO 27001 certified?
- We run clearlea.se in ISO 27001-certified data centres. Our own certification is in preparation.
- How does GDPR deletion work?
- You can delete personal data without losing the audit trail.
- Do you support SSO?
- Yes. Sign-in via SSO, with freely configurable roles and permissions.
- Can we use our own keys and our own model?
- Yes. You can encrypt data with your own keys, connected to your key vault. Then not even we have access. And you can connect your own language model.
- What permissions do AI agents work with?
- Their own. Every workflow step and every agent gets its own permissions and never runs with a user's permissions.
- Can we monitor everything centrally?
- Yes. You can stream logs and telemetry to your SIEM or monitoring via OpenTelemetry.
