Every CloakAPI claim is backed by an artefact you can read, a control you can exercise from your own account, or a cryptographic receipt your finance team can verify offline. We hold no third-party audit attestation — where one would be the only way to satisfy a control, we say so. This page is the index.
Available now, no NDA required: the GDPR Article 28 DPA template, our Article 30 record of processing and data map, the signed SBOM, and cryptographic response receipts you can verify offline. For enterprise procurement questions, a CAIQ, or custom contract edits, contact trust@cloakapi.io.
Architecture you can inspect and artefacts you can verify — not badges we haven't earned.
* On the client-side integration paths, detected PHI is tokenised on your device before it reaches CloakAPI infrastructure, so the gateway holds pseudonymised tokens rather than plaintext identifiers. Detection is best-effort and cloaked is not anonymous — undetected text still crosses. CloakAPI is a data-minimisation tool, not a HIPAA-compliance product.
If your purchasing process needs a specific artefact we don't list here — a completed CAIQ, a custom DPA edit, or an audit-letter request — contact trust@cloakapi.io and we'll work it against your decision timeline. We won't claim an attestation we don't have.
Thirty defensible advantages — verifiable cryptographically or operationally, hard to cheaply copy. Filter by what matters to your review; open any card for the full detail.
The vendors that keep the service running. We don't send your prompt or response content to them; the hosting provider runs the servers it passes through.
| Vendor | What it does / what it never gets | Region | Terms |
|---|---|---|---|
| Anthropic | Upstream model inference (Claude), when your request is routed to it. Receives the text your client sends — tokenised on CloakAPI clients (identifiers our detectors miss pass as written) — and never the map that would re-identify the redacted PII. | US / EU | Art 28 terms ↗ |
| OpenAI | Upstream model inference (GPT), when routed to it. Receives the text your client sends — tokenised on CloakAPI clients (identifiers our detectors miss pass as written) — and never the re-identification map. | US / EU | DPA ↗ |
| Google (Gemini API) | Upstream model inference via the Gemini API (generativelanguage.googleapis.com), when routed to it. Receives the text your client sends — tokenised on CloakAPI clients (identifiers our detectors miss pass as written) — and never the re-identification map. |
US / global | DPA ↗ |
| xAI (Grok) | Upstream model inference (Grok), when routed to it. Receives the text your client sends — tokenised on CloakAPI clients (identifiers our detectors miss pass as written) — and never the re-identification map. | US | xAI terms ↗ |
| DeepSeek | Upstream model inference (DeepSeek), when routed to it. Receives the text your client sends — tokenised on CloakAPI clients (identifiers our detectors miss pass as written) — and never the re-identification map. Hosted in China; disclosed here for transparency — it receives tokenised text, not the re-identification map. | China (PRC) | DeepSeek terms ↗ |
| Stripe | Billing, invoicing and card tokenisation. Receives billing and account data only — never your prompts or responses. No card numbers (PAN) touch CloakAPI. | EU (Stripe Payments Europe) | DPA ↗ |
| AWS (SES) | Transactional and inbound email only — Simple Email Service, an inbound-mail S3 bucket and mail-forwarder Lambdas. Handles email delivery; never prompt or response payloads. No AWS compute or hosting is used. | eu-north-1 (Stockholm) | DPA ↗ |
| Cloudflare | Authoritative DNS only (grey-cloud). Resolves our hostnames; no proxy, no CDN, no WAF, no TLS termination — connections go straight to the EU origin and TLS terminates there. Sees DNS lookups, never request content. | Anycast DNS | DPA ↗ |
| Hetzner | Hosts the gateway relay and related receipt-signing, public JWKS, billing metadata, and staff audit-log services. With the default Level-1 gate enabled, the three inference routes require a supported X-Cloak-Pretokenised header and a valid client MAC over the request body. Requests without the required header receive HTTP 428 and are not relayed. For accepted pre-tokenised inference requests, the gateway verifies the body MAC and checks content-part types for media it cannot tokenize; it does not scan request text for PII or tokenize it. When an accepted request includes an Idempotency-Key, a successful response may be retained in the configured cache for up to 24 hours for replay. The cache stores response-body bytes for replay; it does not scan or tokenize the response. | Nuremberg, DE | DPA ↗ |
This is the high-impact subset — the vendors that touch a live request path or hold account data. The full live sub-processor list, with region, purpose and 30-day change-notification subscription, is published at /legal/subprocessors. Customers can subscribe at trust@cloakapi.io for 30-day advance notice of any change.
Gateway responses can carry a cryptographic receipt under the OpenReceipt spec (ECDSA P-256) when one was issued. You — or your auditor — can verify that receipt offline with the independent verifier at signedreceipts.org: v3 receipts embed the client key, and gateway countersignatures verify against the public JWKS published at api.cloakapi.io. No CloakAPI account required.
Paste any receipt JSON. The verifier checks the signature against the published JWKS, validates the canonical hash chain, and shows you exactly which upstream model was used, when, and under what privacy tier — without sending the receipt back to us.
The public JSONL feed shows the latest published seed state for tenants who opt in; it is not a receipt-issuance log or the full seed-rotation history. The response carries a Gateway HMAC-SHA256 value in its header. A separate Merkle API exposes content-free event leaves, HMAC-SHA256 tree heads, and inclusion/consistency proofs for recorded events. Leaf writes are best-effort; a saved tree head can test later consistency, but these surfaces do not prove every event was captured or that an unsaved history was never rewritten.
The JSONL feed below carries an HMAC-SHA256 response value made with a Gateway-held key; it is separate from receipt signatures. The per-seed endpoints under /api/transparency/seeds return ECDSA-signed responses that can be checked against the published JWKS. Tenants opt in or out per-environment from settings.
GET https://api.cloakapi.io/api/v1/transparency/seeds.jsonl
Service availability and incident postmortems are published openly. Vulnerability reports go to a coordinated disclosure programme with a public hall of fame.
Per-region, per-component health for the gateway, portal, desktop sync, and transparency log. SEV-3+ incidents trigger a public postmortem within 5 business days.
Coordinated-disclosure policy, scope, safe-harbour terms, response SLAs, and a public hall of fame for researchers who help us harden the platform.
Everything procurement and legal usually ask for, linked from one page.
Cyber liability and errors & omissions (E&O) insurance is not currently carried. If your procurement process requires a Certificate of Insurance, contact trust@cloakapi.io — coverage can be bound as part of an enterprise engagement. Full insurance status →
Procurement, security review, custom DPA edits, or audit-letter requests — any of the addresses below reach a real person, not a queue.
DPA, CAIQ, audit letters, sub-processor questions.
DPA counter-signing, contract redlines, data-residency commitments.