Enterprise security, for people and agents alike.
MainFoundry runs on Microsoft Azure's enterprise infrastructure with EU data residency. And the AI agents working in your business are held to the same standard as your team — same sign-in, same permissions, and a full audit trail for every job.
Every agent plays by your rules.
Agents act only through a registry of 112 governed tools. What each one may touch is set by its permission class — and everything it does is on the record.
The foundation, in plain terms.
Straight answers on how MainFoundry is built and run.
- Multi-tenant isolation
- Every organisation's data is isolated in its own tenant. There are no shared access paths between customers.
- Single sign-on
- Sign in with Microsoft 365 (Entra ID) or Google Workspace. Access is managed centrally with the accounts you already run — no extra passwords.
- Role-based access control
- Permissions follow roles, not individuals. People and agents get exactly the access their role grants — nothing more.
- Azure enterprise infrastructure
- MainFoundry runs on Microsoft Azure enterprise infrastructure, with its network security, monitoring and operational controls.
- Encryption
- Data is encrypted in transit and at rest.
- EU data residency
- Your data is stored and processed within the European Union.
- GDPR
- Built for GDPR compliance, with EU data residency throughout. Data-processing documentation is available on request.
- Your data stays yours
- No customer data is used to train AI models.
Our management system, in full.
MainFoundry is operated by ClearContract ApS. Below are the scope of our information security management system and our information security policy, published as approved. We are working toward ISO/IEC 27001 certification and do not claim it today.
Scope of the ISMS
The Information Security Management System covers the development, operation, support and management of ClearContract ApS’s software-as-a-service platforms – the ClearContract contract lifecycle management platform and the MainFoundry agentic business platform – including the handling of customer data, contract documents, platform metadata and source code, and the supporting cloud infrastructure hosted on Microsoft Azure in European regions. The ISMS applies to all directors, founders, employees, interns and contractors of ClearContract ApS, operating from Langelandsgade 62, stuen, 8000 Aarhus C, Denmark and from remote working locations, in accordance with the Statement of Applicability (ISMS-03) version 1.0.
Information security policy
ClearContract ApS protects the confidentiality, integrity and availability of the information entrusted to us by our customers, partners and personnel, and of our own information and systems.
We do this by operating an Information Security Management System that meets ISO/IEC 27001:2022, by identifying and treating information security risks systematically, by building security into the design and operation of our platforms, and by making information security part of everyone's job.
We process customer data only for the purposes agreed with the customer, host it with Microsoft Azure in European regions, do not use it to train AI models, and are open with our customers about how their information is protected.
Top management is committed to satisfying the legal, regulatory and contractual requirements that apply to information security, to providing the resources the ISMS needs, and to continually improving the ISMS.
Both statements are controlled documents. The English text is the authoritative version.
Report a security issue