Security
Security and data protection
Contracts are sensitive documents. Indexerly is built accordingly — EU storage, encryption, and deletion that actually deletes.
Traceable audit
Every amount has receipts
This is the audit trail behind every finding: contract text, official index values, and the math that turns it into money.
We show the exact contract wording, not a guessed summary.
Base period and comparison period are tied to the correct official index.
The formula is shown step by step so the amount can be checked.
Data stored within the EU
All customer data — documents, extracted fields, and calculations — is stored with Supabase in an EU region. No data leaves the EU for storage.
Encryption
TLS in transit, encryption at rest. Documents live in private storage buckets with signed, time-limited access links.
Access model
Row-level security isolates each organization’s data. Only authenticated users linked to the organization can read its contracts.
AI processing
Contract text is sent through OpenRouter solely for analysis. Every request requires Zero Data Retention routing to an inference provider that neither stores nor trains on the content.
Retention and deletion
Deletion is handled manually during private beta to prevent accidental loss. The account owner requests permanent deletion through kontakt@indexerly.com; documents, extracted data and calculations are then removed.
Sub-processors
Vercel (hosting), Supabase (database and EU storage), OpenRouter and the selected inference provider (AI analysis with Zero Data Retention), and Resend (email). The current list is confirmed with customer agreements and the DPA.
Data Processing Agreement
We sign DPAs with all customers. Email kontakt@indexerly.com and we'll send our standard agreement.