Skip to main content

Trust & Security

Trust you can verify.

Trust is not a claim you make; it is a set of things a buyer can check. Calafai's comes down to four, each with the specifics behind it, not just the promise.

Pillar 01 · Rigor

Nothing reaches you on one pass.

Three independent challenge teams read it before you do.

Adversarial review, independent grading, and automatic reruns are built into the pipeline, not bolted on when a client complains.

  • No invented sources
  • Every claim documented
  • Checked from three independent angles

Three independent teams, three AI model families

Challenge teams: adversarial review before the work reaches you.

Not just sourced. Pressure-tested. The industry calls these red teams: each runs on a different top-tier AI model family, so no model gets to approve its own reasoning, and each carries one adversarial mandate: weak assumptions, fabricated sources, or the perspectives a single analyst would skip.

Red Team 1

Logic & Assumptions

Stress-tests the deliverable for internal contradictions and weak assumptions. If the conclusion rests on a premise that doesn't hold, this team names it.

Red Team 2

Factual Accuracy & Sources

Verifies attribution, source quality, and citation accuracy. Strips hallucinated quotes and flags claims that don't have a real provenance.

Red Team 3

Completeness & Blind Spots

Identifies what a single analyst would miss: stakeholder perspectives, implementability gaps, and the work that should have been in scope.

The teams cross-compare their findings across model families before anything ships. When two or more flag the same issue, the finding is marked high-confidence and gets re-run before the deliverable lands. The work doesn't reach you until they've signed off, or told you exactly what they couldn't verify.

One deliverable, many independent checks

The challenge teams are the most visible check, not the only one. Before work starts, each task gets its own definition of done, and an independent reviewer grades the finished work against it. Work that lands below the bar is critiqued, revised, and rerun automatically, and a revision only replaces the original when it scores better. Key claims are re-verified blind: the checker answers the question without seeing the draft, and the two answers are compared. The citations that carry the recommendation are checked for whether they actually support it, not just whether the links exist. Even your own inputs are handled with care: a premise pasted into a brief is flagged for confirmation, not silently built on. And when a report reads too smooth, all confidence and no residual uncertainty, that gets challenged too.

Responsible AI output

Every deliverable is quality-scored before it reaches you. Source claims are verified and graded by reliability. Conclusions are challenged for gaps, weak evidence, and unsupported assumptions by three independent red teams, each running on a different top-tier AI model family, and their findings are cross-compared before delivery: no model approves its own reasoning. Financial assumptions are extracted and made testable. We hold AI-generated strategy work to the same standard a principal consultant would apply to their own team's output.

Pillar 02 · Control

You are never just pressing a button and hoping for the best.

You frame it, steer it, and make the call. Calafai never starts without your green light.

The work is directed by you. Calafai sharpens and pressure-tests your thinking; the judgment, and the decision, stay yours. Redirect it whenever you want.

  • You frame it, steer it, and make the call
  • It never starts without your green light
  • Redirect it whenever you want

Access control

Role-based access control with four permission levels: Owner, Admin, Member, and Viewer. Authentication uses JWT tokens with secure session management and automatic refresh. API keys are SHA-256 hashed before storage, scoped by permission level and optionally by project, and revocable at any time. Every request is scoped to the authenticated user's organization. Rate limiting is enforced across all endpoints.

Sharing & access

Client report links are served exclusively over TLS, the same transport layer that protects everything else on the platform. Share tokens are SHA-256 hashed before storage; the raw token is never held in the database. Any link can be revoked by the engagement owner at any time with immediate effect: the next request against a revoked token is rejected before any content is served.

Pillar 03 · Privacy & Security

What you tell Calafai stays yours.

We do not train on your data. Ever. Not us, not our providers.

Your strategy work is some of your most sensitive thinking. It is isolated, encrypted, and built to SOC 2 and ISO 27001 control frameworks.

  • We do not train on your data. Not us, not our providers.
  • Your data is never shared
  • Built to SOC 2 and ISO 27001 control frameworks, with European data protection law built in from day one.

Tenant data isolation

Every organization's data is isolated at the database level using PostgreSQL Row-Level Security (RLS). This is not application-level filtering that a code bug could bypass. The database engine itself enforces tenant boundaries on every query, every time. Your projects, deliverables, and conversations are never visible to other customers.

Encryption

Data at rest is encrypted with AES-256. Data in transit is protected by TLS 1.3. If you bring your own LLM API keys, they are encrypted with per-tenant Fernet keys (AES-128-CBC + HMAC-SHA256) before storage and never stored in plaintext. Backups inherit the same encryption standards from our infrastructure providers.

AI governance: your data does not train AI

Calafai routes every engagement through enterprise or API contractual terms with model providers that prohibit training on tenant data. Your briefs, attachments, and outputs are not used to train Claude, GPT, Gemini, Grok, or any other model. Encrypted-at-rest storage and PostgreSQL row-level tenant isolation enforce the same boundary at the infrastructure layer.

No single AI company runs your engagement end to end. Work is routed task by task to the model best suited to it, across the providers below, and the orchestration, the quality control, and the assembled deliverable stay inside Calafai's pipeline, not inside any one provider's product.

Calafai is designed to meet the transparency obligations of EU AI Act Article 50: you always know you are working with AI, and every deliverable carries a machine-readable AI-generated marking. For procurement and legal teams, our request-ready statement is available today: read the EU AI Act Article 50 Transparency Statement (PDF) (opens in a new tab).

Model providers Calafai routes traffic to, with usage, data-processing terms, and EU DPA status for each.
ProviderUsed ForData ProcessingEU DPA Status
Anthropic (Claude)Writing, strategy, full-stackAPI, no training on input dataIncorporated by reference (public DPA via API Terms)
OpenAI (GPT and reasoning models)Research, reasoning, image generationAPI, no training (API Terms)Incorporated by reference (public DPA via API Terms)
Google (Gemini API, paid tier)Multimodal analysis, document processingAPI paid tier, no training (Gemini API Terms)Incorporated by reference (paid-tier Data Processing Addendum); Vertex AI / GCP migration pending
xAI (Grok)Strategic reasoning, efficient routingAPI, enterprise terms, no trainingDPA pending counter-signature
Perplexity (Sonar)AI search, live web-grounded answersAPI, no training (Sonar Terms), zero retention by defaultIncorporated by reference (DPA via API Terms)
Mistral AIEuropean models, EU-resident processingAPI, paid tier, EU-hosted, no training (Commercial Terms)Incorporated by reference (DPA via Commercial Terms)
Self-hosted (Qwen via Ollama)Code and simple support tasks; client-local model configurations on request (Enterprise)No external data transferN/A, self-hosted

About the paperwork, plainly: most of our provider DPAs today are incorporated by reference, we accepted each provider's standard API Terms, which include the published DPA, rather than separately negotiated, counter-signed enterprise PDFs. That is normal for a seed-stage SaaS and is the standard contractual posture across the industry at our scale; we flag it here because procurement reviewers ask. xAI's counter-signed DPA is being closed. Google traffic runs on the Gemini API paid tier, where Google's terms state that prompts and responses are not used to improve Google's products and processing falls under Google's Data Processing Addendum; a move to Vertex AI / Google Cloud remains on our roadmap for enterprise and EU-residency configurations. Mistral AI runs on its paid tier with EU-hosted endpoints and anchors EU-residency configurations for Enterprise engagements. Tenant data is not used for training on any provider regardless of paperwork form.

Need a specific provider excluded for internal policy reasons? That becomes a custom engagement, contact us to set up a call.

Data privacy & GDPR

Calafai B.V. is incorporated in the Netherlands and built with European data protection regulation from day one. Full data portability via one-click export. Right to deletion with cascade removal across all projects, deliverables, and run history, with audit trail anonymization. Cookie consent management is built in. Data processing agreements are available on request for enterprise customers.

Security

Calafai is built to SOC 2 and ISO 27001 control frameworks: the same access control, change management, and audit-logging discipline those frameworks require. Formal certification is staged as enterprise procurement requires it, and any certificate earns a place on this page the day it is issued. Our infrastructure providers, Supabase (database and authentication), Vercel (web application), and Railway (compute), are themselves SOC 2 Type II certified, with encrypted-at-rest storage across the board. Security headers are enforced platform-wide: Content Security Policy, HTTP Strict Transport Security, X-Frame-Options, Cross-Origin Resource Policy, and Permissions-Policy. Webhook deliveries to your systems are signed with HMAC-SHA256 for authenticity verification. The baseline is European security standards, among the world's most demanding, and the standard we hold ourselves to.

Data residency

Production hosting is in the United States today. For Enterprise engagements that require EU data residency, we scope and stand up an EU-resident configuration as part of your contract. The way Calafai is built, that is a scoped setup rather than a re-architecture, so it moves quickly once we agree on what you need. There are real trade-offs worth discussing, and we will walk you through them. Contact us to start that conversation.

Pillar 04 · Honesty

You always know how much weight the work can bear.

Every deliverable arrives graded, and every AI output is marked as AI.

How strong the work is, where it is weak, and what produced it: scored deliverables, flagged claims, verified sources, and EU AI Act Article 50 transparency on every output.

  • Every deliverable arrives graded
  • Strong spots and soft spots marked, before you stake anything on it
  • We tell you where a convincing report still needs your eyes

We show you the weak spots

Most AI tools hand you a confident wall of text. Calafai grades the work and shows you the grade. Every deliverable is scored before it reaches you, and the parts that score poorly are not smoothed over: claims that could not be verified are flagged for your review, sources are graded by reliability, and when the red teams cannot confirm something, the deliverable says so instead of hiding it. You see where the work is strong, where it is thin, and where your judgment is still needed, before you stake anything on it.

EU AI Act compliance

Calafai is a limited-risk AI system under Regulation (EU) 2024/1689 (the AI Act). In plain English: every output we produce is marked as AI-generated. Every PDF carries machine-readable metadata. Every PPTX carries OOXML-property markers. Every conversational output in the Thinking Partner and the client portal carries an inline AI badge. Your readers always know what they are looking at. We use only model providers we actually route traffic to, published in full on our subprocessors page, with provider, location, and DPA status, and we update that page whenever the list changes. Calafai's outputs are advisory: a human reviews and decides, so we do not engage GDPR Article 22 on solely-automated decision-making, and we contractually require customers who republish to inform the public to perform their own human review under EU AI Act Article 50(4). For AI-Act-specific questions, including AI literacy under Article 4 or our limited-risk classification under Article 6, write to [email protected].

Audit trail

Over 100 distinct action types are tracked: data access, configuration changes, authentication events, admin actions, API key usage, and project lifecycle events. Every record includes timestamp, user attribution, and metadata. Audit logs are tamper-evident and available to organization owners.

How we operate

Accessible by design. Accountable when something breaks.

Two habits that never show up in a feature list: who can use the product, and what happens the moment we get something wrong.

Accessibility

Accessibility is built into Calafai from the first commit, not retrofitted at the end. Semantic structure, full keyboard operability, visible focus states, and contrast that never depends on color alone are part of how the product is designed. It is how the founder practiced design, product development, and team leadership his entire career, and is one of Calafai's principles, so the people who rely on assistive technology get the same product as everyone else.

Incident response

Security issues can be reported to [email protected]. We acknowledge reports within 24 hours and provide resolution timelines within 72 hours. Platform status and scheduled maintenance are communicated proactively. We do not currently operate a public bug bounty program, but responsible disclosure is welcomed and credited.

Security questions?

We can provide SOC 2 documentation from our infrastructure providers, data processing agreements, our public subprocessors list, and enterprise procurement questionnaire responses. If your team has specific compliance requirements, we will work with you directly.

Contact the security team