Vendor Security & Compliance Fact Sheet
A summary of cajeX's technical setup, data handling, and compliance posture for vendor risk review.
Last updated: August 18, 2026
Company & legal entity
- Legal entity
- cajeX ApS
- Jurisdiction
- Denmark (CVR 46387538)
- Governing law
- Danish law; venue City Court of Copenhagen
- Privacy / DPA contact
- privacy@cajex.ai
Infrastructure & hosting
Standard deployments run on Cloudflare's global edge network — Workers (compute), D1 (database), and R2 (object storage) — with Cloudflare-managed DDoS protection and rate limiting. There is no customer-managed hardware in this model.
For regulated or data-residency-sensitive customers, cajeX offers Bring Your Own Cloud (BYOC): the data plane deploys into the customer's own AWS, Azure, GCP, or on-prem environment. The only outbound call is the AI review API, which can be disabled entirely.
Encryption
- At rest: platform storage encrypted at rest (AES-256); AI-provider credentials use per-workspace key derivation; service secrets stored as one-way hashes.
- In transit: TLS 1.3 on all traffic.
Access control & identity
- Role-based access control (RBAC), signed-token validation on every request.
- Enterprise SSO via Microsoft Entra ID (OIDC/SAML), with SCIM for automated user provisioning.
- Confidential-project visibility restricted to assigned members.
Tenant isolation
Standard plans share infrastructure with logical isolation enforced at the repository layer: every query is scoped by a mandatory workspace key, so no code path can return another workspace's rows.
Enterprise plans upgrade to a dedicated database and dedicated object store per workspace — a physical boundary, independent workspace-scoped backups, and no shared failure modes with other customers.
Audit logging & monitoring
- Workspace-scoped audit log covering user actions; 90-day retention on standard plans, longer on higher tiers.
- Correlation-ID tracing across services for incident investigation.
- Automated managed backups; independent, workspace-scoped backups on Enterprise/dedicated infrastructure.
AI processing & data use
As of August 2026, the platform default model is United States-based (OpenAI), and document extraction defaults to a second United States-based provider (Google) — standard usage does not route content to a China-based provider. Each workspace can also pick its own AI model in Settings → AI: Kimi and Mistral run natively inside Cloudflare Workers AI, so that content never leaves Cloudflare's infrastructure. A workspace only sends content to MiniMax (based in China) if it is specifically configured to use a MiniMax model — see the sub-processor table below. For full control over which vendor processes their data, Enterprise customers can use Bring Your Own Key (BYOK) to route AI calls through their own model endpoint instead of any of the above.
Customer data, directives, and AI output are never used to train or fine-tune any AI model. Only anonymised technical telemetry is used to operate and secure the service. Customers retain all rights to their data and AI output.
Data retention, return & deletion
- Data is retained while the account is active, or as needed to provide the service.
- On termination, data is deleted or returned within 30 days; a deletion certificate is available on request.
- Individual data-subject deletion requests are fulfilled within 30 days.
Availability
cajeX makes commercially reasonable efforts to maintain availability. No specific uptime percentage is guaranteed by default; contractual SLA terms can be discussed for Enterprise agreements.
Compliance posture
Sub-processors
AI-assisted processing is performed by whichever model provider is in effect for a workspace — the platform default, or a model explicitly selected. As of August 2026 the platform default is United States-based; selecting a Cloudflare-hosted model avoids engaging any external AI sub-processor entirely.
| Vendor | Purpose | Location | Data involved |
|---|---|---|---|
| Cloudflare, Inc. | Compute, database, object storage, edge network, and inference for Cloudflare-hosted models (Kimi, Mistral). | United States | All Service data. |
| OpenAI | AI-assisted review, generation, and chat processing. The platform default model as of August 2026 — engaged for every workspace unless a different model is selected. | United States | Content processed by AI features, for workspaces using the default or an OpenAI model. |
| AI-assisted document extraction (the default for this function as of August 2026), and AI-assisted review for workspaces configured to use a Gemini model. | United States | Documents submitted for extraction, and content submitted for AI review for workspaces using this model. | |
| Anthropic | AI-assisted review processing, only for workspaces configured to use an Anthropic Claude model. | United States | Content submitted for AI review, for workspaces using this model only. |
| MiniMax | AI-assisted review processing, only for workspaces that specifically configure a MiniMax model — not the platform default. | China | Content submitted for AI review, for workspaces using this model only. |
| Stripe, Inc. | Payment processing and billing. | United States | Billing and payment data only — no architecture or governance data. |
| Resend | Transactional email delivery. | United States | Email address and notification content only. |
MiniMax is located outside the EEA and its transfer safeguard is not yet finalized — it is not the platform default and is only engaged if a workspace specifically configures a MiniMax model. Workspaces with EU data-residency requirements should not select a MiniMax model; every other option in this table is United States-based. For full control over which vendor processes their data, Enterprise customers may also enable Bring Your Own Key (BYOK) to route AI calls to a self-configured endpoint instead; that vendor relationship belongs to the customer, not cajeX.
The Data Processing Agreement maintains the current sub-processor list and the 30-day objection process for changes.
This fact sheet reflects cajeX's practices as of the date above and is provided for vendor evaluation purposes. It is a plain-language summary, not a substitute for the definitive Terms of Service, Data Processing Agreement, or a signed security addendum — those govern in case of any conflict. For updates or a specific questionnaire response, contact privacy@cajex.ai.