Back to ClauseBridge
Trust

Security & Trust Center

The essentials on how ClauseBridge protects customer information, who can access it, what may be uploaded, and what assurance we can provide today. Security, IT and privacy teams can request more detailed documentation.

Version 1.0 · Last reviewed August 2026

Status statement

ClauseBridge is designed with security and data protection in mind. Security capabilities do not by themselves constitute regulatory certification or authorisation for processing controlled or classified information.

01

Security & Data Protection

  • Customer content — projects, clause assessments, Company Positions and uploaded documents — belongs to the customer and is processed only to deliver the Service.
  • All application traffic is served over encrypted HTTPS/TLS connections.
  • ClauseBridge runs on managed cloud platforms for hosting, database, authentication and file storage. ClauseBridge does not operate its own servers or data-centre hardware.
  • Each organisation's data is separated logically and checked on every database request, so one customer cannot reach another customer's information.
  • Access by ClauseBridge personnel is limited to what is necessary to support, secure and operate the Service.
  • ClauseBridge does not sell customer content and does not use customer content to build public editorial material.
02

Access & Account Security

  • Everything beyond the public website requires an authenticated user account.
  • New accounts must confirm their email address before the account can be used.
  • Passwords and sessions are handled by a managed authentication platform; password reset is available from the sign-in page.
  • Access is organisation-based: users see the projects, documents and positions belonging to their own organisation.
  • Roles (user, reviewer, editor, administrator) are stored and enforced on the server, not in the browser. A browser cannot grant itself elevated access.
  • Colleagues gain access only when an authorised user of the organisation invites them.
  • Multi-factor authentication and enterprise single sign-on (Microsoft Entra ID, SAML) are planned and not available today.
03

Data Handling & Confidentiality

  • Organisations are logically separated. Projects, documents, assessments and Company Positions are scoped to the owning organisation.
  • Information is visible only to authorised users of your organisation, and to ClauseBridge personnel where necessary for support, security and operation.
  • Cross-organisation visibility only happens deliberately: a user invited into your organisation, or a share link created by one of your authorised users.
  • AI analysis runs only when a user explicitly starts it, and only the text needed for that analysis is sent to the AI provider. AI output is decision support and is reviewed by a person.
  • Uploaded documents are restricted by file type and size, and are deleted together with the project or document they belong to.

Classified information must not be uploaded

ClauseBridge is not an accredited system for classified information at any level.

Do not upload national or NATO classified material (for example RESTRICTED, CONFIDENTIAL, SECRET or TOP SECRET), regardless of who produced the document.

Controlled and export-controlled information

The standard ClauseBridge environment is not approved for Controlled Unclassified Information (CUI), Federal Contract Information (FCI), Covered Defense Information (CDI), export-controlled technical data (ITAR/EAR) or documents carrying distribution or dissemination restrictions.

Do not upload such information unless ClauseBridge has confirmed in writing that your organisation's environment is authorised for that specific category. Encryption and access control alone do not make this information acceptable to upload.

Questions before uploading, or an accidental upload to report: security@clausebridge.no. Do not include the restricted content itself in your message.

Suitable for ClauseBridge: public FAR/DFARS and solicitation material, and ordinary business-confidential contract information such as internal clause positions, commercial assessments and project notes.

04

Privacy

ClauseBridge processes personal data as a processor for customer workspaces, and as a controller for its own account, billing and marketing data. Legal bases, categories of data and data subject rights are described in the Privacy Policy.

ClauseBridge does not state that all processing takes place in Norway, the EEA or the EU. Customer information — in particular text submitted for AI analysis — may be processed outside Norway and the EEA, including in the United States. Where a specific data-residency arrangement is required, contact the security team before processing regulated information.

A standard data processing agreement and the current subprocessor list are available on request.

05

Compliance & Assurance

ClauseBridge separates technical security controls from formal regulatory compliance. The table below states our position framework by framework. No entry is shown as certified, compliant or authorised without verified evidence supporting that exact statement.

FrameworkCurrent statusNotes
GDPRApplicable / ImplementedClauseBridge processes personal data as a processor for customer workspaces and as a controller for its own account and marketing data. See the Privacy Notice. A standard data processing agreement is available on request.
NIST SP 800-171Under AssessmentClauseBridge is not assessed against SP 800-171 and makes no compliance claim. Control mapping is being reviewed internally.
CMMCNot CertifiedClauseBridge holds no CMMC certification at any level.
DFARS 252.204-7012Not CertifiedClauseBridge does not represent the standard environment as meeting the safeguarding and reporting requirements of this clause.
ISO/IEC 27001Not CertifiedNo certification. Practices are being aligned with recognised control families as the company matures.
SOC 2Not CertifiedNo SOC 2 Type I or Type II report exists.
FedRAMPNot ApplicableClauseBridge is not offered as a U.S. federal agency cloud service and holds no FedRAMP authorisation.
ITAR-related controlsUnder AssessmentNo ITAR-specific technical controls, personnel screening or access segmentation are represented as implemented.
CUI processing (standard environment)Not SupportedThe standard ClauseBridge environment is not approved for CUI. Contact the security team before any CUI is considered.
Classified informationNot SupportedClauseBridge is not an accredited system for classified information at any level.
NATO classified informationNot SupportedClauseBridge holds no NATO security accreditation and must not be used for NATO classified information.

Documentation available during supplier review

  • Security Overview (PDF)Planned
  • Data Processing AgreementPlanned
  • Subprocessor listActive
  • Technical and organisational security measuresPlanned
  • Security questionnaire responsesPlanned
  • Data flow overviewPlanned
  • AI processing overviewActive

ClauseBridge does not issue certifications or third-party assurance reports it does not hold.

Request security documentation
06

Security & Privacy Contact

Need more detailed security information?

Security, IT and privacy teams may request additional information for supplier assessment and due diligence. We provide detailed material directly rather than publishing it here.

Security
security@clausebridge.no

Security questions, supplier assessments, incidents, vulnerabilities, and questions about sensitive or controlled information.

Privacy
privacy@clausebridge.no

GDPR, personal data, data subject requests, data processing agreements.

Legal
legal@clausebridge.no

Contractual security requirements, Terms and customer agreements.

Request security documentation

Submit the form and your request is sent directly to the ClauseBridge security team. Please do not include classified, controlled or export-controlled content.

Security responsibility

ClauseBridge provides technical safeguards intended to protect information processed through the Service. Customers remain responsible for determining whether ClauseBridge is appropriate for the sensitivity, classification, contractual restrictions and regulatory requirements applicable to their information.

Reviewed August 2026. See also the See also the Terms & Conditions and Privacy Policy.