Security

Enterprise security, for people and agents alike.

MainFoundry runs on Microsoft Azure's enterprise infrastructure with EU data residency. And the AI agents working in your business are held to the same standard as your team — same sign-in, same permissions, and a full audit trail for every job.

Approval gate
Awaiting approval Pay out €1,240
Audit trailjob #2041 · logged end to end
Agent governance

Every agent plays by your rules.

Agents act only through a registry of 112 governed tools. What each one may touch is set by its permission class — and everything it does is on the record.

Platform security

The foundation, in plain terms.

Straight answers on how MainFoundry is built and run.

Multi-tenant isolation
Every organisation's data is isolated in its own tenant. There are no shared access paths between customers.
Single sign-on
Sign in with Microsoft 365 (Entra ID) or Google Workspace. Access is managed centrally with the accounts you already run — no extra passwords.
Role-based access control
Permissions follow roles, not individuals. People and agents get exactly the access their role grants — nothing more.
Azure enterprise infrastructure
MainFoundry runs on Microsoft Azure enterprise infrastructure, with its network security, monitoring and operational controls.
Encryption
Data is encrypted in transit and at rest.
EU data residency
Your data is stored and processed within the European Union.
GDPR
Built for GDPR compliance, with EU data residency throughout. Data-processing documentation is available on request.
Your data stays yours
No customer data is used to train AI models.

ISO/IEC 27001

Our management system, in full.

MainFoundry is operated by ClearContract ApS. Below are the scope of our information security management system and our information security policy, published as approved. We are working toward ISO/IEC 27001 certification and do not claim it today.

Scope of the ISMS

The Information Security Management System covers the development, operation, support and management of ClearContract ApS’s software-as-a-service platforms – the ClearContract contract lifecycle management platform and the MainFoundry agentic business platform – including the handling of customer data, contract documents, platform metadata and source code, and the supporting cloud infrastructure hosted on Microsoft Azure in European regions. The ISMS applies to all directors, founders, employees, interns and contractors of ClearContract ApS, operating from Langelandsgade 62, stuen, 8000 Aarhus C, Denmark and from remote working locations, in accordance with the Statement of Applicability (ISMS-03) version 1.0.

Information security policy

ClearContract ApS protects the confidentiality, integrity and availability of the information entrusted to us by our customers, partners and personnel, and of our own information and systems.

We do this by operating an Information Security Management System that meets ISO/IEC 27001:2022, by identifying and treating information security risks systematically, by building security into the design and operation of our platforms, and by making information security part of everyone's job.

We process customer data only for the purposes agreed with the customer, host it with Microsoft Azure in European regions, do not use it to train AI models, and are open with our customers about how their information is protected.

Top management is committed to satisfying the legal, regulatory and contractual requirements that apply to information security, to providing the resources the ISMS needs, and to continually improving the ISMS.

Both statements are controlled documents. The English text is the authoritative version.

Report a security issue

Put governed agents to work.

Get started