Every CloakAPI claim is backed by an artefact you can read, a control you can exercise from your own account, or a cryptographic receipt your finance team can verify offline. We hold no third-party audit attestation — where one would be the only way to satisfy a control, we say so. This page is the index.
Available now, no NDA required: the GDPR Article 28 DPA template, our Article 30 record of processing and data map, the signed SBOM, and cryptographic response receipts you can verify offline. For enterprise procurement questions, a CAIQ, or custom contract edits, contact trust@cloakapi.io.
Architecture you can inspect and artefacts you can verify — not badges we haven't earned.
* On the client-side integration paths, detected PHI is tokenised on your device before it reaches CloakAPI infrastructure, so the gateway holds pseudonymised tokens rather than plaintext identifiers. Detection is best-effort and cloaked is not anonymous — undetected text still crosses. CloakAPI is a data-minimisation tool, not a HIPAA-compliance product.
If your purchasing process needs a specific artefact we don't list here — a completed CAIQ, a custom DPA edit, or an audit-letter request — contact trust@cloakapi.io and we'll work it against your decision timeline. We won't claim an attestation we don't have.
Thirty defensible advantages — verifiable cryptographically or operationally, hard to cheaply copy. Filter by what matters to your review; open any card for the full detail.
The vendors that keep the service running. None of them receive your prompt or response content.
| Vendor | What it does / what it never gets | Region | Terms |
|---|---|---|---|
| Anthropic | Upstream model inference (Claude), when your request is routed to it. Receives tokenised text only — never your raw prompt, and never the map that would re-identify the redacted PII. | US / EU | Art 28 terms ↗ |
| OpenAI | Upstream model inference (GPT), when routed to it. Receives tokenised text only — never the raw prompt or the re-identification map. | US / EU | DPA ↗ |
| Google (Gemini API) | Upstream model inference via the Gemini API (generativelanguage.googleapis.com), when routed to it. Receives tokenised text only — never the raw prompt or the re-identification map. |
US / global | DPA ↗ |
| xAI (Grok) | Upstream model inference (Grok), when routed to it. Receives tokenised text only — never the raw prompt or the re-identification map. | US | xAI terms ↗ |
| DeepSeek | Upstream model inference (DeepSeek), when routed to it. Receives tokenised text only — never the raw prompt or the re-identification map. Hosted in China; disclosed here for transparency — only tokenised text ever reaches it. | China (PRC) | DeepSeek terms ↗ |
| Stripe | Billing, invoicing and card tokenisation. Receives billing and account data only — never your prompts or responses. No card numbers (PAN) touch CloakAPI. | EU (Stripe Payments Europe) | DPA ↗ |
| AWS (SES) | Transactional and inbound email only — Simple Email Service, an inbound-mail S3 bucket and mail-forwarder Lambdas. Handles email delivery; never prompt or response payloads. No AWS compute or hosting is used. | eu-north-1 (Stockholm) | DPA ↗ |
| Cloudflare | Authoritative DNS only (grey-cloud). Resolves our hostnames; no proxy, no CDN, no WAF, no TLS termination — connections go straight to the EU origin and TLS terminates there. Sees DNS lookups, never request content. | Anycast DNS | DPA ↗ |
| Hetzner | Hosts the blind relay gateway — receipt-signing, public JWKS, billing metadata, staff audit log. No customer prompts or responses: tokenisation runs on the device before egress and the zero-payload invariant is enforced in CI. | Nuremberg, DE | DPA ↗ |
This is the high-impact subset — the vendors that touch a live request path or hold account data. The full live sub-processor list, with region, purpose and 30-day change-notification subscription, is published at /legal/subprocessors. Customers can subscribe at trust@cloakapi.io for 30-day advance notice of any change.
Every gateway response carries a cryptographic receipt signed under the OpenReceipt spec (ECDSA P-256). You — or your auditor — can verify any receipt offline with the independent verifier at signedreceipts.org: v3 receipts embed the client key, and gateway countersignatures verify against the public JWKS published at api.cloakapi.io. No CloakAPI account required.
Paste any signed receipt JSON. The verifier checks the signature against the published JWKS, validates the canonical hash chain, and shows you exactly which upstream model was used, when, and under what privacy tier — without sending the receipt back to us.
CloakAPI publishes a per-tenant transparency log: an append-only feed of cryptographic seeds that lets any verifier confirm CloakAPI never silently rotated a tenant's signing key, never silently changed routing policy, and never ran a "shadow" tenant against the published spec.
The seed feed is JSONL, append-only, and signed under the same ECDSA P-256 keys as receipts. Tenants opt in or out per-environment from settings.
GET https://api.cloakapi.io/api/v1/transparency/seeds.jsonl
Service availability and incident postmortems are published openly. Vulnerability reports go to a coordinated disclosure programme with a public hall of fame.
Per-region, per-component health for the gateway, portal, desktop sync, and transparency log. SEV-3+ incidents trigger a public postmortem within 5 business days.
Coordinated-disclosure policy, scope, safe-harbour terms, response SLAs, and a public hall of fame for researchers who help us harden the platform.
Everything procurement and legal usually ask for, linked from one page.
Cyber liability and errors & omissions (E&O) insurance is not currently carried. If your procurement process requires a Certificate of Insurance, contact trust@cloakapi.io — coverage can be bound as part of an enterprise engagement. Full insurance status →
Procurement, security review, custom DPA edits, or audit-letter requests — any of the addresses below reach a real person, not a queue.
DPA, CAIQ, audit letters, sub-processor questions.
DPA counter-signing, contract redlines, data-residency commitments.