Skip to content
Clarium

Trust & Security

Last updated: 20 August 2026

Clarium is a GDPR compliance platform built entirely on Microsoft Azure. Your data stays within the European Union, on enterprise-grade infrastructure that Microsoft independently certifies. We are transparent about what we certify ourselves and what we rely on Azure for — this page is your single source of truth, and every claim is date-stamped and sourced.

Compliance status

Clarium is built on Microsoft Azure, an enterprise-grade platform independently certified to SOC 2 Type II and ISO 27001. These certifications cover Azure's infrastructure layer, which underpins our service. Cyber Essentials is on our roadmap as we continue to strengthen our own controls.

Last verified: 20 August 2026. Source: Microsoft SOC 2 and Microsoft ISO 27001 compliance offerings.

Hosting & data residency

All Clarium processing is within the European Union. Primary: Azure North Europe (Ireland). DR: Azure West Europe (Netherlands). AI inference: Azure Sweden Central. We may relocate between Azure EU regions to manage capacity or support new features; this page will be updated and affected customers notified in advance.

Relocating between Azure EU regions is not a sub-processor change, so it does not trigger an Article 28(2) re-consent cycle. We notify affected customers as a courtesy, not as a 28-day contractual duty.

Last verified: 20 August 2026. Source: Microsoft Azure region pairs.

Encryption

Data is encrypted in transit and at rest using Microsoft Azure's platform encryption. In transit, Azure services use TLS 1.2 or later. At rest, Azure Storage Service Encryption encrypts data with AES-256, and Azure SQL Database uses Transparent Data Encryption (TDE). These are Microsoft's documented controls for the services we use; we do not assert additional cipher details beyond what Microsoft documents.

Last verified: 20 August 2026. Source: Microsoft Azure encryption overview.

Access control

Access to the Clarium application is protected by Microsoft Entra ID single sign-on by default, with no manual credentials. Access to production infrastructure is restricted to named personnel on a least-privilege basis and governed by Microsoft's identity and access controls.

Last verified: 20 August 2026. Source: Microsoft Entra ID.

Application security

The Clarium application is developed with security in mind: input validation at trust boundaries, least-privilege access, and dependency and vulnerability management as part of our release process. We rely on Microsoft Azure's platform security for the underlying infrastructure.

Last verified: 20 August 2026.

Data protection & data subject rights

As per your DPA terms, Clarium acts as a data processor on your documented instructions. We support you in fulfilling data subject rights requests (GDPR Articles 15–22), including access, rectification, erasure, restriction, portability and objection, within the timelines required by GDPR.

In the event of a personal data breach, we will notify you without undue delay and within 72 hours of becoming aware of the breach, as set out in your DPA terms. We maintain a breach log and support your own notification obligations to the relevant supervisory authority (for example the Jersey Office of the Information Commissioner, JOIC).

Last verified: 20 August 2026. See our DPA for the contractual terms.

Sub-processors

We use a small set of carefully selected sub-processors, all bound by data processing agreements and operating within the European Union. A complete, current list is maintained on our Sub-processors page.

Data Processing Agreement

A GDPR-compliant DPA is available for all customers. It covers the controller/processor relationship, sub-processors, data location, technical measures, data subject rights, breach notification, audit rights and data deletion. See our DPA page for details and to request a signed copy.

Incident response

Security incidents are triaged and escalated to named personnel. For incident response and security matters, contact us at [email protected]. For data protection and privacy matters, contact us at [email protected].

Retention and deletion: upon termination of services, we delete or return all personal data within 30 days, unless retention is required by law, as set out in your DPA terms.

Vulnerability management: we track and remediate vulnerabilities in our dependencies and application code as part of our regular release cadence, and we rely on Microsoft's patching of the Azure platform.

Last verified: 20 August 2026.

Due diligence questionnaire (self-serve)

The most common questions we receive in security due diligence, answered here. Each answer is date-stamped and sourced to Microsoft where it relates to Azure.

1. Does Clarium hold security certifications?

No. Clarium is built on Microsoft Azure, an enterprise-grade platform independently certified to SOC 2 Type II and ISO 27001, covering Azure's infrastructure layer which underpins our service. Cyber Essentials is on our roadmap. (Last verified:20 August 2026.)

2. What happens in the event of a personal data breach?

We notify you without undue delay and within 72 hours of becoming aware of a breach, as per your DPA terms, and support your own notification obligations to the relevant supervisory authority. (Last verified: 20 August 2026.)

3. How long is data retained?

Upon termination of services, we delete or return all personal data within 30 days, unless retention is required by law. (Last verified: 20 August 2026.)

4. Where is data hosted?

All Clarium processing is within the European Union. Primary: Azure North Europe (Ireland). DR: Azure West Europe (Netherlands). AI inference: Azure Sweden Central. (Last verified: 20 August 2026.)

5. Is data transferred outside the EU/EEA?

No. All processing is within the European Union; we do not transfer personal data outside the EEA. (Last verified: 20 August 2026.)

6. How is data encrypted?

Data is encrypted in transit and at rest using Microsoft Azure's platform encryption. In transit, Azure services use TLS 1.2 or later. At rest, Azure Storage Service Encryption encrypts data with AES-256, and Azure SQL Database uses Transparent Data Encryption (TDE). (Last verified: 20 August 2026. Source: Microsoft Azure encryption overview.)

7. Who has access to customer data?

Access to the Clarium application is protected by Microsoft Entra ID single sign-on by default. Access to production infrastructure is restricted to named personnel on a least-privilege basis. (Last verified: 20 August 2026.)

8. How does Clarium handle data subject access requests (DSARs)?

As per your DPA terms, we support you in fulfilling data subject rights requests (GDPR Articles 15–22) within the timelines required by GDPR. (Last verified: 20 August 2026.)

9. What sub-processors does Clarium use?

A small set of carefully selected sub-processors, all bound by data processing agreements and operating within the European Union. See our Sub-processors page for the current list. (Last verified: 20 August 2026.)

10. Is a DPA available?

Yes. A GDPR-compliant DPA is available for all customers. See our DPA page. (Last verified: 20 August 2026.)

11. How does Clarium manage vulnerabilities?

We track and remediate vulnerabilities in our dependencies and application code as part of our regular release cadence, and we rely on Microsoft's patching of the Azure platform. (Last verified: 20 August 2026.)

12. Can Clarium be audited?

You have the right to audit our compliance with the DPA, as set out in your DPA terms. We can provide Microsoft Azure's SOC 2 Type II and ISO 27001 audit reports (covering Azure's infrastructure layer) upon request, and we support your audit of our application-layer controls. (Last verified: 20 August 2026.)

Updates to this page

We keep this page current. When our security posture, residency, or sub-processors change, we update this page and, where required, notify affected customers in advance. The "last verified" stamps above reflect the most recent review of each claim.

Service status

For security or privacy questions, contact [email protected] or [email protected].