Data Residency & Encryption
Employee data stays in the region, encrypted under a key that is yours alone
Claro is a managed service hosted in the Southeast Asia region. Every tenant holds its own AES-256-GCM data encryption key, every table carries row-level isolation, and crypto-erasure gives you a clean answer to an erasure request, with no infrastructure for your team to run or patch.
Regional hosting, per-tenant encryption, and row-level isolation are enforced on every request, with nothing for your team to install, upgrade, or patch.
For banks, insurers, and government agencies, where employee data is held is often as important as what a platform does with it. Claro runs as a managed service in the Southeast Asia region, so personal data stays inside the geography your regulators and your own policy expect it to. Every table carries row-level tenant isolation, resolved on every authenticated request, so one organization's records are never in the same query path as another's. Personally identifiable fields such as email addresses are encrypted at rest with AES-256-GCM under a data encryption key that belongs to your tenant and no other, with blind indexes so an encrypted field like email can still be searched without ever decrypting the column.
Data subject requests are handled two ways, matched to the scope of the request. Crypto-erasure destroys an entire tenant's encryption key, permanently rendering all of that tenant's PII unreadable without touching a single row, which is the mechanism for whole-tenant erasure. Field-level user erasure anonymizes a single user's PII, replacing their email with an encrypted sentinel and nulling other personal fields while leaving a tombstone timestamp, for individual erasure requests. A configurable data retention policy enforces how long data is kept per tenant, run by a scheduled background job rather than a manual cleanup task. Because Claro is managed, security patches and platform fixes reach you continuously, with no upgrade project to budget for and no maintenance window your team has to plan.
What you get
Hosted in the Southeast Asia region
Claro runs as a managed service in-region, so employee data stays inside the geography your regulators and internal policy expect, without your team standing up any infrastructure.
A separate AES-256-GCM key per tenant
Personally identifiable fields are encrypted at rest under a data encryption key unique to your tenant, and the platform refuses to start unless its encryption keys are configured.
Row-level tenant isolation
Every record carries a tenant identifier and every authenticated request is scoped to it, so no query can reach across organizations, however it is constructed.
Blind indexes for searchable encrypted fields
Fields like email are encrypted at rest but remain searchable through a blind index, so lookups never require decrypting the whole column.
Crypto-erasure for whole-tenant deletion
Destroying a tenant's data encryption key permanently renders all of that tenant's PII unreadable without touching individual rows, satisfying whole-tenant erasure obligations.
Field-level user erasure
Individual erasure requests anonymize a single user's PII, an encrypted sentinel for email and null for other personal fields, with a tombstone timestamp marking when the erasure occurred.
Configurable retention, enforced automatically
A per-tenant retention policy is enforced by a scheduled background job, rather than a manual process someone has to remember to run.
Built for Indonesia
Data residency without an infrastructure project
Many Indonesian banks and government agencies are required, or strongly prefer, to keep employee data inside the region. Claro answers that with regional hosting plus cryptographic separation: your tenant's data sits behind its own AES-256-GCM key, isolated at row level on every request, and can be made permanently unreadable by destroying that key. You get the control a self-managed stack was meant to buy you, without your team owning the patching, the backups, or the upgrade path.
- Managed hosting in the Southeast Asia region, so employee data stays in-region
- A separate AES-256-GCM data encryption key per tenant, plus row-level isolation on every request
- Crypto-erasure and field-level user erasure satisfy UU PDP (Indonesia's data protection law) data-subject rights
- Configurable, per-tenant data retention enforced automatically
- Security fixes ship continuously, with no upgrade project or maintenance window on your side
Frequently asked questions
Claro is a managed service hosted in the Southeast Asia region, so employee data stays in-region rather than being processed in a distant cloud. Our team can confirm the specific region and the contractual residency commitment before you sign.
Related pages
Risk Scoring & Analytics
A behavior-driven human risk score built from clicks, reports, and training activity, with department views, benchmarking, and board-ready exports.
Learn morePhishing Reporting
A one-click Outlook and Gmail report button that matches reported emails to simulations, rewards reporters, and routes real threats to your admins.
Learn moreVishing Simulation
Branching voice-call simulations with typed script nodes, DTMF-driven flows, and outcome capture that feeds directly into risk scoring and training.
Learn moreSee it running on your own domain
Book a walkthrough with our team and we'll show you this capability configured for your organization's compliance requirements and language needs.
Book a walkthrough