Data Handling

How Clausi processes your code

What Data Is Processed

  • Source code files you select for scanning
  • File paths and directory structure
  • Code content for AI analysis

Where It's Processed

  • File discovery, clause matching, caching, and report generation all run on your machine
  • Clausi operates no scan server. Your code is never sent to Clausi, so there is nothing for us to store, log, or expose
  • To perform the AI analysis, the CLI sends relevant code to the AI provider you choose — your own Anthropic or OpenAI account, under your own API key
  • That provider bills you directly. Clausi is not in the payment path or the data path

Retention

  • Clausi retains no code and no scan results, because neither reaches us
  • Findings, reports, and the local cache are written to your project directory and your home directory, under your control
  • Data retention for the AI analysis itself is governed by your agreement with Anthropic or OpenAI, not by us

Accounts

  • An account is optional and is not required to scan
  • If you sign in, we store your email and an API token — never your code

What This Does and Doesn't Mean

Clausi never receives your source code. That is not the same as claiming your code never leaves your machine: running a scan does transmit code to the AI provider you selected, over your own account and key. The practical difference for a security review is that Clausi adds no new vendor, no new data processor, and no DPA to negotiate — the only external party involved is one you have already chosen and can revoke at any time.

Contact

Questions about data handling? Email us at support@clausi.ai