Skip to main content

    Trust · Compliance

    Professional Secrecy Mode (§203 StGB)

    For German Berufsgeheimnisträger — lawyers, tax advisors, auditors, notaries, patent attorneys — bound by §203 StGB in conjunction with §43e BRAO, §62a StBerG, §50a WPO, §26a BNotO and §39a PAO.

    What the mode enforces

    • EU-only inference. Every AI call routes exclusively through model deployments on EU-resident endpoints (Mistral, Azure OpenAI EU, Anthropic via AWS Frankfurt, Gemini EU).
    • Strict BYOK. Every member of a secrecy-mode org must use their own workspace key; shared Lovable AI Gateway credits are refused.
    • Zero prompt retention. Prompt bodies are never stored server-side. Only metadata (timestamp, model deployment, user id) is retained in the audit log, kept for 10 years per §50 BRAO analog.
    • §203-bound sub-processors. Every sub-processor with potential access is flagged as §203-bound on the sub-processor list. Changes: 30 days' advance notice.
    • Countersigned addendum. The org owner countersigns the Berufsgeheimnisträger-Zusatzvereinbarung before the mode can be activated.

    Live enforcement status

    We publish this table live from our database rather than a marketing claim. Rows without a checkmark are on the rollout plan but not yet hard-enforced server-side.

    Honest scope — what we do not claim

    §203 StGB compliance is a shared responsibility. Keypra provides the contractual and technical scaffolding; the professional remains individually responsible for lawful use, client consent where required, and choice of models. We do not represent that using Keypra in itself discharges the professional's duties under §43e BRAO / §62a StBerG.

    This addendum is a first draft prepared by Keypra product/legal. Countersignature is disabled in-product until the version is cleared by a qualified German lawyer.