GDPR — Art 28 DPA + Art 30 RoPA published EU data plane — Hetzner Nuremberg HIPAA — PHI tokenised on-device PCI DSS v4.0 — out of scope (SAQ-A)

Built for trust.
Provable, not just promised.

Every CloakAPI claim is backed by an artefact you can read, a control you can exercise from your own account, or a cryptographic receipt your finance team can verify offline. We hold no third-party audit attestation — where one would be the only way to satisfy a control, we say so. This page is the index.

Need the full trust packet?

Available now, no NDA required: the GDPR Article 28 DPA template, our Article 30 record of processing and data map, the signed SBOM, and cryptographic response receipts you can verify offline. For enterprise procurement questions, a CAIQ, or custom contract edits, contact trust@cloakapi.io.

01 — Compliance posture

Where we stand — honestly.

Architecture you can inspect and artefacts you can verify — not badges we haven't earned.

GDPR / EU
Documents published
BasisArticle 28 DPA + Article 30 RoPA
Data planeEU-only (Hetzner Nuremberg)
Verifiable receipts
Live now
WhatReceipts when issued (ECDSA P-256)
ProofVerify offline against public JWKS
HIPAA
PHI tokenised on-device
StatusData-minimisation tool, not a HIPAA product
NoteDetected PHI is tokenised before it reaches us*
PCI DSS v4.0
SAQ-A — out of scope
StatusOut of CDE by construction
WhyNo cardholder data (PAN) stored — Stripe is the card processor
Next stepNone unless we ever store PAN (not planned)

* On the client-side integration paths, detected PHI is tokenised on your device before it reaches CloakAPI infrastructure, so the gateway holds pseudonymised tokens rather than plaintext identifiers. Detection is best-effort and cloaked is not anonymous — undetected text still crosses. CloakAPI is a data-minimisation tool, not a HIPAA-compliance product.

If your purchasing process needs a specific artefact we don't list here — a completed CAIQ, a custom DPA edit, or an audit-letter request — contact trust@cloakapi.io and we'll work it against your decision timeline. We won't claim an attestation we don't have.

01b — Structural advantages

The thirty moats, in full.

Thirty defensible advantages — verifiable cryptographically or operationally, hard to cheaply copy. Filter by what matters to your review; open any card for the full detail.

01Client-side
Token-level redaction at your edge
02Client-side
No cloud AI needed to keep PII off the wire
03Client-side
Names caught on-device
04Client-side
Local LLM-as-judge on your hardware
05Client-side
Files and images extracted on-device
06Architecture
A blind relay
07Key custody
No map, no recovery
08Deployment
Complete-local: air-gap ready
09Verifiable proof
Receipts you can verify.
10Verifiable proof
Two-party receipts when both signatures ran
11Tamper-evidence
Status page
12Retention
Bodies not stored by default
13Enforcement
Body logging and cache controls
14Data protection
Strong data-protection jurisdiction
15Compliance
Erasure receipts
16Regulatory
We hold no PHI or regulated PII
17Coverage
International PII coverage
18Metadata
Prompt-pool privacy on CloakAPI keys
19Open protocols
Open, auditable, no lock-in
20Crypto
One crypto stack at every layer
21Transparency
Transparency reports
22Billing
Auditable invoices
23Routing
Cost-aware multi-provider arbitrage
24Pricing
Three flat rates. No tiers
25Operational
One vendor, no infra burden
26Platform
Build on CloakAPI
27Platform
Inheritable privacy — same receipts downstream
28Platform
Enforceable fix distribution
29Platform
Metered-relay lock in our SDKs
30Platform
Verifiable third-party builds
02 — Sub-processors

Who else is involved — and what each one sees.

The vendors that keep the service running. We don't send your prompt or response content to them; the hosting provider runs the servers it passes through.

VendorWhat it does / what it never getsRegionTerms
Anthropic Upstream model inference (Claude), when your request is routed to it. Receives the text your client sends — tokenised on CloakAPI clients (identifiers our detectors miss pass as written) — and never the map that would re-identify the redacted PII. US / EU Art 28 terms ↗
OpenAI Upstream model inference (GPT), when routed to it. Receives the text your client sends — tokenised on CloakAPI clients (identifiers our detectors miss pass as written) — and never the re-identification map. US / EU DPA ↗
Google (Gemini API) Upstream model inference via the Gemini API (generativelanguage.googleapis.com), when routed to it. Receives the text your client sends — tokenised on CloakAPI clients (identifiers our detectors miss pass as written) — and never the re-identification map. US / global DPA ↗
xAI (Grok) Upstream model inference (Grok), when routed to it. Receives the text your client sends — tokenised on CloakAPI clients (identifiers our detectors miss pass as written) — and never the re-identification map. US xAI terms ↗
DeepSeek Upstream model inference (DeepSeek), when routed to it. Receives the text your client sends — tokenised on CloakAPI clients (identifiers our detectors miss pass as written) — and never the re-identification map. Hosted in China; disclosed here for transparency — it receives tokenised text, not the re-identification map. China (PRC) DeepSeek terms ↗
Stripe Billing, invoicing and card tokenisation. Receives billing and account data only — never your prompts or responses. No card numbers (PAN) touch CloakAPI. EU (Stripe Payments Europe) DPA ↗
AWS (SES) Transactional and inbound email only — Simple Email Service, an inbound-mail S3 bucket and mail-forwarder Lambdas. Handles email delivery; never prompt or response payloads. No AWS compute or hosting is used. eu-north-1 (Stockholm) DPA ↗
Cloudflare Authoritative DNS only (grey-cloud). Resolves our hostnames; no proxy, no CDN, no WAF, no TLS termination — connections go straight to the EU origin and TLS terminates there. Sees DNS lookups, never request content. Anycast DNS DPA ↗
Hetzner Hosts the gateway relay and related receipt-signing, public JWKS, billing metadata, and staff audit-log services. With the default Level-1 gate enabled, the three inference routes require a supported X-Cloak-Pretokenised header and a valid client MAC over the request body. Requests without the required header receive HTTP 428 and are not relayed. For accepted pre-tokenised inference requests, the gateway verifies the body MAC and checks content-part types for media it cannot tokenize; it does not scan request text for PII or tokenize it. When an accepted request includes an Idempotency-Key, a successful response may be retained in the configured cache for up to 24 hours for replay. The cache stores response-body bytes for replay; it does not scan or tokenize the response. Nuremberg, DE DPA ↗

This is the high-impact subset — the vendors that touch a live request path or hold account data. The full live sub-processor list, with region, purpose and 30-day change-notification subscription, is published at /legal/subprocessors. Customers can subscribe at trust@cloakapi.io for 30-day advance notice of any change.

03 — Receipts → independent verification

You don't have to trust us.

Gateway responses can carry a cryptographic receipt under the OpenReceipt spec (ECDSA P-256) when one was issued. You — or your auditor — can verify that receipt offline with the independent verifier at signedreceipts.org: v3 receipts embed the client key, and gateway countersignatures verify against the public JWKS published at api.cloakapi.io. No CloakAPI account required.

Verify a receipt

Paste any receipt JSON. The verifier checks the signature against the published JWKS, validates the canonical hash chain, and shows you exactly which upstream model was used, when, and under what privacy tier — without sending the receipt back to us.

04 — Transparency log

Public tenant seed-state feed.

The public JSONL feed shows the latest published seed state for tenants who opt in; it is not a receipt-issuance log or the full seed-rotation history. The response carries a Gateway HMAC-SHA256 value in its header. A separate Merkle API exposes content-free event leaves, HMAC-SHA256 tree heads, and inclusion/consistency proofs for recorded events. Leaf writes are best-effort; a saved tree head can test later consistency, but these surfaces do not prove every event was captured or that an unsaved history was never rewritten.

Live endpoint

The JSONL feed below carries an HMAC-SHA256 response value made with a Gateway-held key; it is separate from receipt signatures. The per-seed endpoints under /api/transparency/seeds return ECDSA-signed responses that can be checked against the published JWKS. Tenants opt in or out per-environment from settings.

GET https://api.cloakapi.io/api/v1/transparency/seeds.jsonl

05 — Incident response & status

Live state, in public.

Service availability and incident postmortems are published openly. Vulnerability reports go to a coordinated disclosure programme with a public hall of fame.

Live status

Per-region, per-component health for the gateway, portal, desktop sync, and transparency log. SEV-3+ incidents trigger a public postmortem within 5 business days.

Vulnerability disclosure

Coordinated-disclosure policy, scope, safe-harbour terms, response SLAs, and a public hall of fame for researchers who help us harden the platform.

07 — Insurance

Cyber liability & E&O coverage.

Cyber liability and errors & omissions (E&O) insurance is not currently carried. If your procurement process requires a Certificate of Insurance, contact trust@cloakapi.io — coverage can be bound as part of an enterprise engagement. Full insurance status →

08 — Contact

Talk to a human.

Procurement, security review, custom DPA edits, or audit-letter requests — any of the addresses below reach a real person, not a queue.

Trust & compliance

DPA, CAIQ, audit letters, sub-processor questions.

Legal & DPA

DPA counter-signing, contract redlines, data-residency commitments.