BRAO § 43e — Notes on cloud use
Technical and organisational design of Caelex Atlas for use by attorneys-at-law
Effective: 28 July 2026 · Caelex, Julian Polleschner, Berlin · Version 1.1
This page summarises how Caelex Atlas is designed, technically and organisationally, with regard to typical requirements of Section 43e of the Bundesrechtsanwaltsordnung (BRAO — German Federal Lawyers' Act) (use of services). It is an information statement for law firms — not legal advice, not a binding conformity certificate of a bar, and not a substitute for a signed data processing agreement (DPA) with the correct Caelex entity.
Whether use of Atlas is professionally permissible for a particular mandate is a decision the firm takes on its own responsibility (including Section 203 of the German Criminal Code (StGB) and internal policies).
The German version at /legal/brao-43e is the legally binding text. This English version is a convenience translation. In the event of conflict, the German text prevails.
1. Purpose and limits
- Describes TOMs and architectural features of Caelex Atlas
- Does not replace a DPA or a firm's internal clearance
- Does not replace an individual assessment of the duty of confidentiality
- If this page conflicts with a signed contract, the contract governs
2. Security standards (cf. BRAO § 43e(2) no. 1)
- Transmission: TLS (modern on the provider side)
- Storage: AES-256-GCM for sensitive text fields and chat contents per organisation, where enabled
- Tenant isolation: organisation + mandate membership in queries
- Authentication: password plus optional multi-factor authentication (TOTP) and passkeys (WebAuthn/FIDO2) — MFA is available in the product and recommended, but not enforced system-wide
- Audit: organisation-wide, hash-chained audit logs for in-product actions
- Sub-processors: including Neon, Vercel, Anthropic, Cloudflare — provider certifications (e.g. SOC 2 / ISO) are in their trust centres; Caelex itself is not SOC 2 or ISO 27001 certified as of the date of this document
3. Access and personnel (cf. BRAO § 43e(2) no. 2)
Caelex contractually binds staff and contractors with infrastructure access to confidentiality. Sub-processors are engaged under Art. 28 DPAs and, where agreed, additional confidentiality and zero-data-retention clauses. Details: /legal/mitwirkende-en and /legal/sub-processors-en.
4. Data residency (cf. BRAO § 43e(2) no. 3 / GDPR Chapter V)
Client content (database, vault) remains in the EU as intended. Support services (AI fallback, embeddings, email, monitoring) may have third-country exposure and are safeguarded via DPF/SCCs and related instruments, as disclosed in the sub-processor register. Full statement: /legal/data-residency-en.
5. Audit and information rights (cf. BRAO § 43e(2) no. 4)
Under signed contracts and NDA, Caelex will make available, to the extent reasonably practicable: sub-processor lists, TOM descriptions, provider reports (where released), and inspection of relevant audit-log concepts. Concrete deadlines and modalities are governed by the respective contract — not by this webpage alone.
6. AI processing
- Chat and tool text is sent to Anthropic Claude (Atlas: EU-only via Bedrock/Gateway, fail-closed; no US fallback in the product default)
- Product and DPA posture: no use for model training (zero data retention), where contractually agreed with Anthropic
- Atlas outputs are decision-support — not legal advice and not a clearance
7. Deletion and portability
Deletion and export claims are governed by the GDPR and the respective contract. Typical target timescales (not binding without a contract): deletion or export within 30 days after effective termination and request; backup retention is vendor-limited.
8. Insurance
Particulars of insurance cover are available on request via legal@caelex.eu.
Contact
Caelex, Julian Polleschner, Berlinlegal@caelex.euVersion 1.1 · 28 July 2026