TRUST CENTER · EVIDENCE ARCHITECTURE

Trust Center.

Independent verification instead of assurances: custody hashes anyone can re-check, a live engine changelog, and a plain account of how data is handled and protected. No black boxes.

CUSTODY & VERIFICATION

Every screening carries a fingerprint you can check.

Each screening is logged with a SHA-256 custody hash computed over the engine version and thresholds, the geometry, the dataset versions and the signals found. Anyone holding the hash — an auditor, a customer, a customs broker — can re-check the result against what was stored. Screenings are re-hashable; nothing changes silently.

  • /verify/<custody-hash>Paste the 64-character SHA-256 custody hash issued with any screening.
  • /verify/EUDRC-YYYY-NNNNOr the DDS pack reference code printed on an exported evidence pack.

CUSTODY HASH · COMPUTED OVER

ENGINE VERSION + THRESHOLDS

The screening-engine version and the threshold rules in force at screening time.

GEOMETRY

The plot geometry exactly as submitted — coordinates, CRS, area.

DATASET VERSIONS

The pinned version of every dataset consulted: Whisp, Hansen GFC, GLAD/RADD.

SIGNALS

The figures found — loss area, alert counts — and the verdict composed from them.

SHA-256 → ONE-WAY DIGEST

CUSTODY HASH: 8f3a…c21e

RE-HASH MATCHES STORED VALUE

The verify page re-hashes the stored inputs of every lookup and compares them against the published custody value — a match means the record behind the hash is exactly the record that was screened.

ENGINE CHANGELOG · LIVE

When the engine changes, it changes here first.

This table is fetched live from the public API — not hand-written onto the page. Threshold rules, dataset basis and notes for every engine version, in the open.

VERSIONDATETHRESHOLD RULEDATASET BASISNOTES

FETCHING LIVE CHANGELOG…

Every screening’s custody hash pins the engine version it was rendered under — past results never silently change.

DATA HANDLING & RETENTION

What we keep, for how long, and who sees it.

RETENTION

Five years, version-pinned.

Screening inputs, dataset versions and outputs are retained for five years to support EUDR Art. 12 record-keeping. Records are version-pinned: a figure keeps the dataset vintage it was computed against, even after upstream datasets update.

SUPPLIER COLLECTION

Links see a label — never your identity.

Supplier collection links carry only a plot label you choose. Suppliers who submit geometries never see your company name, your customer record, or anything beyond the plots you explicitly share.

PLOT COORDINATES

Treated as potentially personal data.

Plot coordinates can identify a natural person (GDPR Art. 4(1)) — a smallholder farm is often also a home. We handle and protect them accordingly.

DETAILS IN THE PRIVACY POLICY →

SECURITY POSTURE

Controls, stated plainly.

  • OAUTH STATE

    Every login flow carries an HMAC-signed state parameter with a 10-minute time-to-live — one-shot CSRF protection.

  • SESSIONS

    30-day sessions, bound to the account and revocable on sign-out.

  • RATE LIMITS

    Per-endpoint limits on public and authenticated routes — verify lookups, for example, are capped per visitor.

  • SECRETS

    API keys and provider secrets are masked in the admin console and are never displayed un-masked after being saved.

  • AUDIT LOG

    Append-only: administrative actions are recorded immutably and cannot be edited or deleted after the fact.

  • ADMIN BOOTSTRAP

    The administrator account is pinned to the owner. There is no open administrative sign-up path.

HONEST SCOPE EUDR Clear is solo-operated and runs on a single region. The controls above are proportionate to that footprint — stated plainly rather than dressed up in enterprise language.

Professional liability (E&O) insurance: [pending — at launch]

The policy is bound at launch; this chip is removed the day the certificate is in hand — not before.

SUBPROCESSORS

Who touches what.

The complete list of third parties involved in running EUDR Clear — login, email, payments, delivery, hosting, and the upstream datasets we screen against. No others.

SUBPROCESSORROLEPURPOSELOCATION
ResendLOGIN + EMAILOne-time sign-in links and transactional email. No passwords are stored.EU/US — see /legal/privacy
ResendTRANSACTIONAL EMAILAlerts, screening receipts and pack reference codes.EU/US — see /legal/privacy
StripePAYMENTSSubscription billing; card data stays with Stripe.EU/US — see /legal/privacy
CloudflareDELIVERYEdge delivery and denial-of-service protection.EU/US — see /legal/privacy
MySQL / TiDB hostAPPLICATION DATAPrimary datastore: accounts, plots, screenings, custody hashes.EU/US — see /legal/privacy
FAO Whisp · Hansen GFC · GLADUPSTREAM DATASETSScreening evidence layers — queried and version-pinned per screening, never a personal-data store.Public datasets — see /legal/attribution

This list changes only by addition, and changes are announced before they take effect. Data-processing details in the privacy policy →

INDEPENDENCE

EUDR Clear is not a certification body and does not conduct audits. It is not affiliated with, sponsored by, or endorsed by the European Commission or the Food and Agriculture Organization of the United Nations. Screening output is decision-support: it organizes evidence for your risk assessment. The due-diligence obligations — and the due-diligence statement — remain with the operator (EUDR Art. 10).

READ THE FULL DISCLAIMER →

Indicative screening for decision-support only — not a compliance determination, certification, or legal advice. Due-diligence obligations remain with the operator (EUDR Art. 10).

Trust is checkable. Start with one plot.

Free scope-checker — one plot, instant indicative screening, no card required.

Run the scope-checker

Indicative screening for decision-support only — not a compliance determination.