Skip to content

Vendor Security & Compliance Fact Sheet

A summary of cajeX's technical setup, data handling, and compliance posture for vendor risk review.

Last updated: August 18, 2026

Company & legal entity

Legal entity
cajeX ApS
Jurisdiction
Denmark (CVR 46387538)
Governing law
Danish law; venue City Court of Copenhagen
Privacy / DPA contact
privacy@cajex.ai

Infrastructure & hosting

Standard deployments run on Cloudflare's global edge network — Workers (compute), D1 (database), and R2 (object storage) — with Cloudflare-managed DDoS protection and rate limiting. There is no customer-managed hardware in this model.

For regulated or data-residency-sensitive customers, cajeX offers Bring Your Own Cloud (BYOC): the data plane deploys into the customer's own AWS, Azure, GCP, or on-prem environment. The only outbound call is the AI review API, which can be disabled entirely.

Encryption

  • At rest: platform storage encrypted at rest (AES-256); AI-provider credentials use per-workspace key derivation; service secrets stored as one-way hashes.
  • In transit: TLS 1.3 on all traffic.

Access control & identity

  • Role-based access control (RBAC), signed-token validation on every request.
  • Enterprise SSO via Microsoft Entra ID (OIDC/SAML), with SCIM for automated user provisioning.
  • Confidential-project visibility restricted to assigned members.

Tenant isolation

Standard plans share infrastructure with logical isolation enforced at the repository layer: every query is scoped by a mandatory workspace key, so no code path can return another workspace's rows.

Enterprise plans upgrade to a dedicated database and dedicated object store per workspace — a physical boundary, independent workspace-scoped backups, and no shared failure modes with other customers.

Audit logging & monitoring

  • Workspace-scoped audit log covering user actions; 90-day retention on standard plans, longer on higher tiers.
  • Correlation-ID tracing across services for incident investigation.
  • Automated managed backups; independent, workspace-scoped backups on Enterprise/dedicated infrastructure.

AI processing & data use

As of August 2026, the platform default model is United States-based (OpenAI), and document extraction defaults to a second United States-based provider (Google) — standard usage does not route content to a China-based provider. Each workspace can also pick its own AI model in Settings → AI: Kimi and Mistral run natively inside Cloudflare Workers AI, so that content never leaves Cloudflare's infrastructure. A workspace only sends content to MiniMax (based in China) if it is specifically configured to use a MiniMax model — see the sub-processor table below. For full control over which vendor processes their data, Enterprise customers can use Bring Your Own Key (BYOK) to route AI calls through their own model endpoint instead of any of the above.

Customer data, directives, and AI output are never used to train or fine-tune any AI model. Only anonymised technical telemetry is used to operate and secure the service. Customers retain all rights to their data and AI output.

Data retention, return & deletion

  • Data is retained while the account is active, or as needed to provide the service.
  • On termination, data is deleted or returned within 30 days; a deletion certificate is available on request.
  • Individual data-subject deletion requests are fulfilled within 30 days.

Availability

cajeX makes commercially reasonable efforts to maintain availability. No specific uptime percentage is guaranteed by default; contractual SLA terms can be discussed for Enterprise agreements.

Compliance posture

GDPR
Data export & deletion, configurable retention, standard data-subject rights. DPA available on request.
SOC 2 Type IIIn progress — not yet certified
On the pre-GA roadmap.
ISO 27001 / HIPAAIn progress — not yet certified
Not currently certified. Private Cloud / BYOC is designed for HIPAA-style and data-residency requirements, but that is an architecture fit, not a certification.
Additional security documentation — architecture diagrams, the current DPA, or answers to a specific vendor questionnaire (CAIQ, SIG Lite, or your own format) — is available on request via privacy@cajex.ai.

Sub-processors

AI-assisted processing is performed by whichever model provider is in effect for a workspace — the platform default, or a model explicitly selected. As of August 2026 the platform default is United States-based; selecting a Cloudflare-hosted model avoids engaging any external AI sub-processor entirely.

VendorPurposeLocationData involved
Cloudflare, Inc.Compute, database, object storage, edge network, and inference for Cloudflare-hosted models (Kimi, Mistral).United StatesAll Service data.
OpenAIAI-assisted review, generation, and chat processing. The platform default model as of August 2026 — engaged for every workspace unless a different model is selected.United StatesContent processed by AI features, for workspaces using the default or an OpenAI model.
GoogleAI-assisted document extraction (the default for this function as of August 2026), and AI-assisted review for workspaces configured to use a Gemini model.United StatesDocuments submitted for extraction, and content submitted for AI review for workspaces using this model.
AnthropicAI-assisted review processing, only for workspaces configured to use an Anthropic Claude model.United StatesContent submitted for AI review, for workspaces using this model only.
MiniMaxAI-assisted review processing, only for workspaces that specifically configure a MiniMax model — not the platform default.ChinaContent submitted for AI review, for workspaces using this model only.
Stripe, Inc.Payment processing and billing.United StatesBilling and payment data only — no architecture or governance data.
ResendTransactional email delivery.United StatesEmail address and notification content only.

MiniMax is located outside the EEA and its transfer safeguard is not yet finalized — it is not the platform default and is only engaged if a workspace specifically configures a MiniMax model. Workspaces with EU data-residency requirements should not select a MiniMax model; every other option in this table is United States-based. For full control over which vendor processes their data, Enterprise customers may also enable Bring Your Own Key (BYOK) to route AI calls to a self-configured endpoint instead; that vendor relationship belongs to the customer, not cajeX.

The Data Processing Agreement maintains the current sub-processor list and the 30-day objection process for changes.

This fact sheet reflects cajeX's practices as of the date above and is provided for vendor evaluation purposes. It is a plain-language summary, not a substitute for the definitive Terms of Service, Data Processing Agreement, or a signed security addendum — those govern in case of any conflict. For updates or a specific questionnaire response, contact privacy@cajex.ai.