The essentials on how ClauseBridge protects customer information, who can access it, what may be uploaded, and what assurance we can provide today. Security, IT and privacy teams can request more detailed documentation.
Version 1.0 · Last reviewed August 2026
ClauseBridge is designed with security and data protection in mind. Security capabilities do not by themselves constitute regulatory certification or authorisation for processing controlled or classified information.
ClauseBridge is not an accredited system for classified information at any level.
Do not upload national or NATO classified material (for example RESTRICTED, CONFIDENTIAL, SECRET or TOP SECRET), regardless of who produced the document.
The standard ClauseBridge environment is not approved for Controlled Unclassified Information (CUI), Federal Contract Information (FCI), Covered Defense Information (CDI), export-controlled technical data (ITAR/EAR) or documents carrying distribution or dissemination restrictions.
Do not upload such information unless ClauseBridge has confirmed in writing that your organisation's environment is authorised for that specific category. Encryption and access control alone do not make this information acceptable to upload.
Questions before uploading, or an accidental upload to report: security@clausebridge.no. Do not include the restricted content itself in your message.
Suitable for ClauseBridge: public FAR/DFARS and solicitation material, and ordinary business-confidential contract information such as internal clause positions, commercial assessments and project notes.
ClauseBridge processes personal data as a processor for customer workspaces, and as a controller for its own account, billing and marketing data. Legal bases, categories of data and data subject rights are described in the Privacy Policy.
ClauseBridge does not state that all processing takes place in Norway, the EEA or the EU. Customer information — in particular text submitted for AI analysis — may be processed outside Norway and the EEA, including in the United States. Where a specific data-residency arrangement is required, contact the security team before processing regulated information.
A standard data processing agreement and the current subprocessor list are available on request.
ClauseBridge separates technical security controls from formal regulatory compliance. The table below states our position framework by framework. No entry is shown as certified, compliant or authorised without verified evidence supporting that exact statement.
| Framework | Current status | Notes |
|---|---|---|
| GDPR | Applicable / Implemented | ClauseBridge processes personal data as a processor for customer workspaces and as a controller for its own account and marketing data. See the Privacy Notice. A standard data processing agreement is available on request. |
| NIST SP 800-171 | Under Assessment | ClauseBridge is not assessed against SP 800-171 and makes no compliance claim. Control mapping is being reviewed internally. |
| CMMC | Not Certified | ClauseBridge holds no CMMC certification at any level. |
| DFARS 252.204-7012 | Not Certified | ClauseBridge does not represent the standard environment as meeting the safeguarding and reporting requirements of this clause. |
| ISO/IEC 27001 | Not Certified | No certification. Practices are being aligned with recognised control families as the company matures. |
| SOC 2 | Not Certified | No SOC 2 Type I or Type II report exists. |
| FedRAMP | Not Applicable | ClauseBridge is not offered as a U.S. federal agency cloud service and holds no FedRAMP authorisation. |
| ITAR-related controls | Under Assessment | No ITAR-specific technical controls, personnel screening or access segmentation are represented as implemented. |
| CUI processing (standard environment) | Not Supported | The standard ClauseBridge environment is not approved for CUI. Contact the security team before any CUI is considered. |
| Classified information | Not Supported | ClauseBridge is not an accredited system for classified information at any level. |
| NATO classified information | Not Supported | ClauseBridge holds no NATO security accreditation and must not be used for NATO classified information. |
ClauseBridge does not issue certifications or third-party assurance reports it does not hold.
Request security documentationNeed more detailed security information?
Security, IT and privacy teams may request additional information for supplier assessment and due diligence. We provide detailed material directly rather than publishing it here.
Security questions, supplier assessments, incidents, vulnerabilities, and questions about sensitive or controlled information.
GDPR, personal data, data subject requests, data processing agreements.
Submit the form and your request is sent directly to the ClauseBridge security team. Please do not include classified, controlled or export-controlled content.
ClauseBridge provides technical safeguards intended to protect information processed through the Service. Customers remain responsible for determining whether ClauseBridge is appropriate for the sensitivity, classification, contractual restrictions and regulatory requirements applicable to their information.
Reviewed August 2026. See also the See also the Terms & Conditions and Privacy Policy.