GDPR — Art 28 DPA + Art 30 RoPA published EU data plane — Hetzner Nuremberg HIPAA — PHI tokenised on-device PCI DSS v4.0 — out of scope (SAQ-A)

Built for trust.
Provable, not just promised.

Every CloakAPI claim is backed by an artefact you can read, a control you can exercise from your own account, or a cryptographic receipt your finance team can verify offline. We hold no third-party audit attestation — where one would be the only way to satisfy a control, we say so. This page is the index.

Need the full trust packet?

Available now, no NDA required: the GDPR Article 28 DPA template, our Article 30 record of processing and data map, the signed SBOM, and cryptographic response receipts you can verify offline. For enterprise procurement questions, a CAIQ, or custom contract edits, contact trust@cloakapi.io.

01 — Compliance posture

Where we stand — honestly.

Architecture you can inspect and artefacts you can verify — not badges we haven't earned.

GDPR / EU
Documents published
BasisArticle 28 DPA + Article 30 RoPA
Data planeEU-only (Hetzner Nuremberg)
Verifiable receipts
Live now
WhatEvery response signed (ECDSA P-256)
ProofVerify offline against public JWKS
HIPAA
PHI tokenised on-device
StatusData-minimisation tool, not a HIPAA product
NoteDetected PHI is tokenised before it reaches us*
PCI DSS v4.0
SAQ-A — out of scope
StatusOut of CDE by construction
WhyNo cardholder data (PAN) stored — Stripe is the card processor
Next stepNone unless we ever store PAN (not planned)

* On the client-side integration paths, detected PHI is tokenised on your device before it reaches CloakAPI infrastructure, so the gateway holds pseudonymised tokens rather than plaintext identifiers. Detection is best-effort and cloaked is not anonymous — undetected text still crosses. CloakAPI is a data-minimisation tool, not a HIPAA-compliance product.

If your purchasing process needs a specific artefact we don't list here — a completed CAIQ, a custom DPA edit, or an audit-letter request — contact trust@cloakapi.io and we'll work it against your decision timeline. We won't claim an attestation we don't have.

01b — Structural advantages

The thirty moats, in full.

Thirty defensible advantages — verifiable cryptographically or operationally, hard to cheaply copy. Filter by what matters to your review; open any card for the full detail.

01Client-side
Token-level redaction at your edge
02Client-side
No cloud AI needed to keep PII off the wire
03Client-side
Names caught on-device
04Client-side
Local LLM-as-judge on your hardware
05Client-side
Files and images extracted on-device
06Architecture
A blind relay — mathematically
07Key custody
No map, no recovery
08Deployment
Complete-local: air-gap ready
09Verifiable proof
Signed receipts on every call
10Verifiable proof
Two-party receipts: client-signed, gateway-countersigned
11Tamper-evidence
Signed status page
12Retention
Zero payload retention
13Enforcement
Zero-payload, CI-enforced
14Data protection
Strong data-protection jurisdiction
15Compliance
Signed erasure receipts
16Regulatory
We hold no PHI or regulated PII
17Coverage
International PII coverage
18Metadata
Prompt-pool privacy on CloakAPI keys
19Open protocols
Open, auditable, no lock-in
20Crypto
One crypto stack at every layer
21Transparency
Signed transparency reports
22Billing
Auditable invoices
23Routing
Cost-aware multi-provider arbitrage
24Pricing
Three flat rates. No tiers
25Operational
One vendor, no infra burden
26Platform
Build on CloakAPI
27Platform
Inheritable privacy — same receipts downstream
28Platform
Enforceable fix distribution
29Platform
Metered-relay lock — the guarantee isn't optional
30Platform
Verifiable third-party builds
02 — Sub-processors

Who else is involved — and why none of them see your data.

The vendors that keep the service running. None of them receive your prompt or response content.

VendorWhat it does / what it never getsRegionTerms
Anthropic Upstream model inference (Claude), when your request is routed to it. Receives tokenised text only — never your raw prompt, and never the map that would re-identify the redacted PII. US / EU Art 28 terms ↗
OpenAI Upstream model inference (GPT), when routed to it. Receives tokenised text only — never the raw prompt or the re-identification map. US / EU DPA ↗
Google (Gemini API) Upstream model inference via the Gemini API (generativelanguage.googleapis.com), when routed to it. Receives tokenised text only — never the raw prompt or the re-identification map. US / global DPA ↗
xAI (Grok) Upstream model inference (Grok), when routed to it. Receives tokenised text only — never the raw prompt or the re-identification map. US xAI terms ↗
DeepSeek Upstream model inference (DeepSeek), when routed to it. Receives tokenised text only — never the raw prompt or the re-identification map. Hosted in China; disclosed here for transparency — only tokenised text ever reaches it. China (PRC) DeepSeek terms ↗
Stripe Billing, invoicing and card tokenisation. Receives billing and account data only — never your prompts or responses. No card numbers (PAN) touch CloakAPI. EU (Stripe Payments Europe) DPA ↗
AWS (SES) Transactional and inbound email only — Simple Email Service, an inbound-mail S3 bucket and mail-forwarder Lambdas. Handles email delivery; never prompt or response payloads. No AWS compute or hosting is used. eu-north-1 (Stockholm) DPA ↗
Cloudflare Authoritative DNS only (grey-cloud). Resolves our hostnames; no proxy, no CDN, no WAF, no TLS termination — connections go straight to the EU origin and TLS terminates there. Sees DNS lookups, never request content. Anycast DNS DPA ↗
Hetzner Hosts the blind relay gateway — receipt-signing, public JWKS, billing metadata, staff audit log. No customer prompts or responses: tokenisation runs on the device before egress and the zero-payload invariant is enforced in CI. Nuremberg, DE DPA ↗

This is the high-impact subset — the vendors that touch a live request path or hold account data. The full live sub-processor list, with region, purpose and 30-day change-notification subscription, is published at /legal/subprocessors. Customers can subscribe at trust@cloakapi.io for 30-day advance notice of any change.

03 — Receipts → independent verification

You don't have to trust us.

Every gateway response carries a cryptographic receipt signed under the OpenReceipt spec (ECDSA P-256). You — or your auditor — can verify any receipt offline with the independent verifier at signedreceipts.org: v3 receipts embed the client key, and gateway countersignatures verify against the public JWKS published at api.cloakapi.io. No CloakAPI account required.

Verify a receipt

Paste any signed receipt JSON. The verifier checks the signature against the published JWKS, validates the canonical hash chain, and shows you exactly which upstream model was used, when, and under what privacy tier — without sending the receipt back to us.

04 — Transparency log

Per-tenant, append-only, public seed feed.

CloakAPI publishes a per-tenant transparency log: an append-only feed of cryptographic seeds that lets any verifier confirm CloakAPI never silently rotated a tenant's signing key, never silently changed routing policy, and never ran a "shadow" tenant against the published spec.

Live endpoint

The seed feed is JSONL, append-only, and signed under the same ECDSA P-256 keys as receipts. Tenants opt in or out per-environment from settings.

GET https://api.cloakapi.io/api/v1/transparency/seeds.jsonl

05 — Incident response & status

Live state, in public.

Service availability and incident postmortems are published openly. Vulnerability reports go to a coordinated disclosure programme with a public hall of fame.

Live status

Per-region, per-component health for the gateway, portal, desktop sync, and transparency log. SEV-3+ incidents trigger a public postmortem within 5 business days.

Vulnerability disclosure

Coordinated-disclosure policy, scope, safe-harbour terms, response SLAs, and a public hall of fame for researchers who help us harden the platform.

07 — Insurance

Cyber liability & E&O coverage.

Cyber liability and errors & omissions (E&O) insurance is not currently carried. If your procurement process requires a Certificate of Insurance, contact trust@cloakapi.io — coverage can be bound as part of an enterprise engagement. Full insurance status →

08 — Contact

Talk to a human.

Procurement, security review, custom DPA edits, or audit-letter requests — any of the addresses below reach a real person, not a queue.

Trust & compliance

DPA, CAIQ, audit letters, sub-processor questions.

Legal & DPA

DPA counter-signing, contract redlines, data-residency commitments.