Skip to content

Security

Security and data protection

Contracts are sensitive documents. Indexerly is built accordingly — EU storage, encryption, and deletion that actually deletes.

Traceable audit

Every amount has receipts

This is the audit trail behind every finding: contract text, official index values, and the math that turns it into money.

1Clause quote

We show the exact contract wording, not a guessed summary.

2SCB values

Base period and comparison period are tied to the correct official index.

3Calculation

The formula is shown step by step so the amount can be checked.

Data stored within the EU

All customer data — documents, extracted fields, and calculations — is stored with Supabase in an EU region. No data leaves the EU for storage.

Encryption

TLS in transit, encryption at rest. Documents live in private storage buckets with signed, time-limited access links.

Access model

Row-level security isolates each organization’s data. Only authenticated users linked to the organization can read its contracts.

AI processing

Contract text is sent through OpenRouter solely for analysis. Every request requires Zero Data Retention routing to an inference provider that neither stores nor trains on the content.

Retention and deletion

Deletion is handled manually during private beta to prevent accidental loss. The account owner requests permanent deletion through kontakt@indexerly.com; documents, extracted data and calculations are then removed.

Sub-processors

Vercel (hosting), Supabase (database and EU storage), OpenRouter and the selected inference provider (AI analysis with Zero Data Retention), and Resend (email). The current list is confirmed with customer agreements and the DPA.

Data Processing Agreement

We sign DPAs with all customers. Email kontakt@indexerly.com and we'll send our standard agreement.