Legal

Security Notice

Last updated: July 2026

Overview

Security is foundational to Klarum. This notice summarises how we protect the data on our platform. It is a living document and will be expanded as our programme matures. For the current, detailed security package, contact us at security@klarum.com.

Hosting & data residency

The primary database holding customer data is hosted in Germany West Central (Frankfurt). Object storage is provided by Cloudflare R2 with automatic placement.

Generative model inference runs on Amazon Bedrock, and document parsing uses a third-party parsing service established in the United States under EU Standard Contractual Clauses. We are enumerating the exact region of every step in that processing chain and will publish the full list here once each entry has been verified against our production logs; until then this notice makes no blanket residency claim. An earlier revision stated that “the platform is EU-hosted”. That statement was broader than we had verified and is withdrawn. The current sub-processor list, with the region and transfer safeguard for each entry, is in our privacy policy and in the security package available on request.

Tenancy and separation

Klarum is a shared-infrastructure, multi-tenant service. Data belonging to different organisations is separated by access controls in the Klarum application: every request, including every generative request, is constructed only from data the requesting member is authorised to read. A database-level authorisation backstop is our highest-priority security work item and is not yet in place, so separation is enforced by the application layer today.

An earlier revision of this notice stated that the platform is “operated in single-tenant deployments for enterprise customers”. That statement did not describe the architecture and is withdrawn.

Customer data and model training

Customer data is never used to train or fine-tune foundation models, whether by us or by the model provider acting on our behalf. Inference requests are stateless: the provider does not retain prompt content for training, and no persistent per-customer model context is kept.

We do retain the working record of AI-assisted work inside the customer's own tenant - conversation history, generated drafts and extracted fields - because the product would not function otherwise. That material is customer data and is deleted under the deletion terms of the master agreement.

Our own opportunity-ranking models are a separate matter from foundation models. An earlier revision of this notice stated without qualification that customer records are “not used to train shared models”; because that wording covered our ranking models as well, it went further than we could evidence and is withdrawn. An organisation-level control over that use is in progress and will be described here when it ships.

Certifications & compliance

We process personal data in accordance with the GDPR and the Swedish Data Protection Act (2018:218).

Reporting a vulnerability

If you believe you have found a security issue, please email security@klarum.com. We acknowledge reports promptly and will keep you informed as we investigate. Please do not publicly disclose an issue until we have had a reasonable opportunity to address it.

Operator

Klarum Technologies AB

Org. nr: 559536-7979

Stockholm, Sweden

Email: security@klarum.com