That is the difference from pure software vendors: your data is not only covered by a privacy policy, but by criminal-law professional secrecy under section 203 StGB, the requirements of section 50a WPO on IT outsourcing, and a two-track contract system. We did not build Cupel for auditors. We are the auditors.
The moat
Pure software vendors build for auditors. justReporting is a licensed audit firm. That creates a legal difference that no certification can bridge.
Section 203(1)(3) StGB
Certified auditors are designated professional secret-holders. Unauthorised disclosure of client confidences carries a custodial sentence of up to one year. That is not a contractual confidentiality clause but German criminal law, stronger than any ISO standard.
Section 50a WPO
Section 50a WPO (introduced 2017) expressly permits auditors to use external IT providers, including cloud and AI, when six requirements are cumulatively met. For justReporting this is binding professional law, not a voluntary gesture.
GDPR Art. 28
A data processing agreement (DPA) under GDPR Art. 28 covers personal data. For client confidences that fall outside GDPR scope, we additionally provide a professional secrecy agreement under section 203 StGB. A DPA alone is not sufficient for professional secret-holders.
Section 50a WPO
Section 50a WPO defines the conditions under which auditors may use external IT service providers. Cupel meets all six requirements.
Careful selection of the service provider
Section 50a(2) sentence 1
Contract in text form
Section 50a(3) sentence 1
Confidentiality obligation with criminal-law instruction
Section 50a(3) sentence 2 no. 1
Need-to-know principle
Section 50a(3) sentence 2 no. 2
Regulation of the sub-contracting chain
Section 50a(3) sentence 2 no. 3
Right to terminate immediately
Section 50a(2) sentence 2
Your contract is with justReporting GmbH Wirtschaftspruefungsgesellschaft, not with AWS and not with Anthropic. We provide both the DPA and the professional secrecy agreement under section 203 StGB. This responsible-provider model is expressly recognised by the WPK and legal literature as a permissible approach.
AI and your data
Blanket statements help no one. Here is exactly what happens technically, separated by model, user scope, and reference store.
Neither AWS nor Anthropic nor Cupel use your content as training data. Content is processed statelessly and, where needed, used solely as embeddings for reference search, never to train models. AWS Bedrock guarantees this contractually.
Cupel applies strict user isolation. Your uploaded reports, comments, and references are exclusively available within your scope and are never shared with other users. Confidentiality across engagements is architecturally enforced.
When you confirm a comment, that decision is stored as an embedding and improves suggestions exclusively for your own future reviews. This is a reference-search tool, not model training. You can opt out of this use at any time.
Infrastructure
All data is processed and stored in AWS Frankfurt (eu-central-1). No transfer to non-EU regions at any point.
EU data residency
Encryption
AI infrastructure
Other AI tools promise confidentiality. Cupel is liable for it, criminally bound, as a licensed audit firm.
Disclosing data here risks a custodial sentence of up to one year, not a contractual penalty. The strongest confidentiality commitment German law knows.
You contract with justReporting GmbH Wirtschaftspruefungsgesellschaft, not a startup. Section 50a WPO is binding professional law for us.
Operated in AWS Frankfurt, in-region routing, AES-256 encrypted. Data never leaves the European Union.
An ISO standard describes a process framework. Professional secrecy under section 203 StGB is a criminal-law obligation under German law and therefore the strongest confidentiality commitment any provider can make. We are preparing ISO 27001 certification. Our core commitment is a different one: Cupel is itself an audit firm.
Roadmap
We name the gaps rather than hiding them. ISO 27001 is the strength of pure software vendors. Our moat is different: the legal form. Here is what is on the roadmap.
ISO 27001 certification
planned for 2027
First external penetration test
planned for H2 2026
SSO and SAML federation
enterprise tier, planned Q4 2026
BSI C5 attestation
for regulated clients, under review
BYOK (bring your own encryption key)
enterprise tier, under review
Transparency is our answer to missing certifications. An ISO certification is a voluntary process standard. Section 203 StGB is German criminal law and has applied to us from day one.
Sign up to secure early access to Cupel. We get in touch personally, and beta participants receive special conditions at launch.