Your data stays where it belongs

Claridy works inside your financial systems, so security is not a chapter at the back. Here is how we protect your data, how we build with AI, and what has been independently assessed.

CASA Tier 2
Completed
TAC Security, February 2026, cyber score 9.7 out of 10
SOC 2
In finalization
The report goes here once it exists
GDPR
In place
Data processing agreement with every customer
EU AI Act
Limited risk
Transparent, with human oversight

How we protect your data

  • ·Processed and stored within the EU, for every customer.
  • ·We never use your data to train AI models.
  • ·Payments stay with you. Claridy prepares the payment batch and holds a supplier whose IBAN changed, you release it at your own bank. We never hold your bank credentials.
  • ·Read-only where possible. We only write back what you approved, and we change nothing in your ERP configuration.
  • ·Encrypted at rest (AES-256) and in transit (TLS), MFA enforced on admin accounts, daily scans for vulnerable dependencies.
  • ·Permissions per workflow and per entity. Our team only enters your environment on request, and that is logged.
  • ·Monthly cancellable and your data is exportable. Your ERP stays authoritative, so stopping with Claridy does not leave your books stuck anywhere.

How we build with AI

Claridy is not a chat window on your books. AI helps build a workflow, and from then on that workflow runs as fixed code. That makes it boring exactly where you want boring.

A fixed route, not a guess

Execution is fixed code. A workflow that worked yesterday works the same today, and no AI update quietly changes how you book.

Tested on your own history

Every workflow first runs on your own past invoices and bookings, not a demo set. Only when the results hold does it touch anything.

You approve

Claridy proposes, your threshold decides what goes automatically. Anything that moves money always passes a person.

Everything traceable

For every action we record what was read, what was decided, at what score, and what was written back. Searchable, exportable, and made to show your auditor.

Where we stand on the EU AI Act

Claridy works with the accounting and ERP data of businesses. We do not score the creditworthiness of individuals or make decisions the AI Act treats as high risk. So we treat Claridy as a limited-risk AI system and focus on the obligations that apply:

  • ·Transparency. It is always clear that an agent did something, and every action is logged.
  • ·Human oversight. You approve, correct or roll back.
  • ·AI literacy. Our team knows what the systems we build can and cannot do.

We track how the AI Act and its standards develop, and adjust how we work as the rules take effect.

Independently assessed

In February 2026 TAC Security assessed Claridy against CASA Tier 2, built on the OWASP Application Security Verification Standard. All 108 requirements were reviewed, from access control and cryptography to session management and injection prevention.

  • ·CASA Tier 2, carried out by TAC Security, February 2026
  • ·No critical, high or medium findings across the full application
  • ·Cyber score 9.7 out of 10

SOC 2 is in finalization. The report goes here once it exists.

Found a vulnerability?

Let us know and we will work with you to resolve it. We ask that you give us reasonable time to respond before disclosing anything publicly.

hello@claridy.ai

Documents

Data processing agreement · Sub-processor overview · Security overview · CASA Tier 2 audit report on request. Bring your hardest security questions to the demo.

Request the documentation ↗hello@claridy.ai