Klaris Trust Center
Secure AI for regulatory documentation. See how we protect customer data, maintain privacy, and meet recognised security and compliance standards.
Compliance
Compliance

ISO 27001
GDPR
Resources
ISO 27001 Certificate
ISO 27001 Audit Report
Statement of Applicability
Pentest-Letter of Attestation
FAQs
Is Klaris ISO 27001 certified?
Yes. Klaris's Information Security Management System is independently certified to ISO/IEC 27001:2022. The certification covers the security controls and processes used to protect Klaris systems and customer information.
Where is customer data stored and processed?
Customer data is hosted in the European Union, with production data residing in Belgium and managed from the EU and UK. Klaris is designed to maintain EU data residency for customer information.
How does Klaris protect customer data?
Customer data is encrypted in transit using TLS 1.3 and at rest using AES-256. Access to production systems and customer information is restricted using role-based access controls and least-privilege principles. Klaris also maintains security monitoring, vulnerability management and incident-response controls as part of its ISO 27001-certified ISMS.
How do users authenticate to Klaris?
Klaris uses federated authentication through Google and Microsoft. Klaris does not maintain or store application passwords for customer users; authentication is delegated to the user's selected identity provider using standards-based authentication. Customers can therefore apply the authentication and MFA controls configured within their Google or Microsoft environment.
Does Klaris use customer data to train AI models?
No. Customer documents are not used to train or fine-tune Klaris models or third-party AI models. Klaris maintains zero-data-retention arrangements with the third-party LLM providers used in its processing stack so that customer content is used only to perform the requested processing.
Is Klaris GDPR compliant, and is a DPA available?
Yes. Klaris maintains controls designed to comply with EU and UK GDPR. When processing customer-provided information, Klaris generally acts as a data processor on behalf of the customer. A Data Processing Agreement (DPA) is available to customers on request.
How does Klaris protect against data loss and service disruption?
Klaris maintains documented business continuity, disaster recovery and backup procedures. Customer data is backed up using controlled cloud infrastructure, with backups protected through encryption and access controls. Recovery arrangements are tested periodically, and Klaris maintains defined recovery objectives for critical services.
How does Klaris respond to security incidents?
Klaris maintains a documented Security Incident Response Plan covering identification, escalation, containment, investigation, recovery and communication. The plan is tested at least annually. Where an incident affects customer data or services, affected customers are notified in accordance with applicable legal and contractual requirements.
Subprocessors
Google Cloud Platform

Microsoft Azure

Anthropic
Slack

OpenAI

Linear

LlamaIndex

Github

Notion
Monitoring
Continuously monitored by Secureframe