Where your data lives, and how we protect it.
Clause 60 handles commercial contract data for construction professionals. Security and data protection are built into the architecture, not bolted on — here is exactly how, in plain terms, with the independent evidence to back it.
At a glance
1. Your data stays in the UK
- Your documents, your reviews and your account data are stored and processed in the UK (London region).
- The AI analysis runs in the EU (Google Cloud, Belgium) — a UK-to-EU transfer on the UK's adequacy footing. Nothing leaves the UK or EU.
2. Strict isolation between organisations
- Every organisation's data is isolated at the database level, not just in the application, and is designed to fail closed — if the system cannot positively confirm who you are and which organisation you belong to, it returns nothing.
- Within your organisation, access is scoped per project — people see only the projects they are assigned to.
- A cross-organisation access attempt does not return "forbidden", it returns nothing at all. This was specifically probed in our independent penetration test (§6), which found no cross-tenant access.
3. How we protect access
- Multi-factor authentication is mandatory for every user — no exceptions.
- Passwords are hashed with Argon2id and screened against known-breached-password databases, so a password compromised elsewhere cannot be reused here.
- All traffic is encrypted in transit (TLS); data is encrypted at rest.
- Sessions time out after inactivity, and changing your password signs out all other sessions.
- Administrative actions are recorded in an append-only audit trail.
4. The AI layer
- Reviews are produced by a large language model served through Google Cloud's Vertex AI. The model is stateless — it reads only what it is given for a single review and retains nothing between reviews.
- Your data is not used to train AI models.
- Every review records what produced it — the inputs used and the review methodology version — so any report is replayable and defensible.
5. Human-in-the-loop by design
Clause 60 is assistive, not advisory. It supports a qualified reviewer; it does not replace one. Findings are labelled Fact (drawn from your documents) or Inference (the tool's reasoning), and missing information is flagged as missing, never assumed. The professional makes the decision and signs it off.
6. Independent security testing
- Clause 60 has been independently penetration-tested by a CREST-certified firm, covering the web application, the API, file handling and the AI/LLM layer (July–August 2026, retest completed 3 August 2026).
- The test found zero Critical, zero High and zero Medium issues — no cross-tenant data access, no authentication bypass and no privilege escalation — and verified that the prompt-injection defence works: a document attempting to manipulate the review was detected, disregarded and flagged, with no effect on the output.
- The low and informational findings were remediated and verified on retest, with a single informational TLS-configuration item addressed as part of our custom-domain rollout.
- A summary of the test and our management response is available to prospective customers under NDA.
7. Certifications
- Cyber Essentials certified — the UK government-backed scheme (NCSC / IASME), whole-organisation scope (verify certificate).
- Download our Cyber Essentials certificate (PDF)
- ICO registration — Clause 60 Limited is registered with the UK Information Commissioner's Office (no. ZC194083).
8. Insurance
Clause 60 Limited carries business insurance underwritten by Hiscox:
- Technology Professional Indemnity: £2,000,000
- Cyber & Data: £1,000,000
- Public & Products Liability: £1,000,000
- Employers' Liability: £10,000,000
Certificates are available to customers on request.
9. Your data, your control
- Export: you can obtain a copy of your organisation's data on request.
- Deletion: we delete your data on request and at the end of your engagement, including removing uploaded documents from storage.
- Retention: we keep your data only as long as needed to provide the service — for the duration of your engagement and for 12 months after a project is completed, after which it is securely deleted — sooner on request, with a 90-day export window if you leave.
10. Sub-processors & documents
We use the following sub-processors to deliver the service, each under Article 28 UK GDPR terms. We give advance notice of any additions or replacements.
- Google Cloud — hosting, storage and AI inference (Claude via Google Vertex AI). Customer Content is stored in the UK; inference runs in the EU. Customer Content is not used to train AI models and is not shared with the model publisher.
- Microsoft 365 — transactional email (account, invitation, notification and password-reset messages). No Customer Content.
- Stripe — billing and invoicing. No Customer Content.
- Questions about security or data protection: admin@clause60.com.
Clause 60 Limited, company no. 17317413 (UK). Security & data protection: admin@clause60.com.
