Private, physically isolated, compliance-first
Full data sovereignty. From deployment architecture to access control, security is Claway’s default — not an add-on.
Private / hybrid deployment
Choose deployment by region, data type, and use case; data stays with the enterprise, off the public cloud — balancing security, compliance, and efficiency.
D.I.U physical isolation
A complete AI role runs on the company’s own local server; data is physically isolated, memory accrues — never on the cloud, never off the internal network.
Multi-tenant hard isolation
Each channel’s role, memory, skills, and KB scope are isolated at the SQL layer, blocking cross-tenant leakage.
Knowledge-base upper bound
Each channel’s retrieval scope is enforced by the system; the model cannot escalate beyond it, and unlisted channels get no KB access.
2FA Operator Console
A Cookie + TOTP two-factor operator console, safe to expose publicly — no per-machine credential sharing.
Compliance & cross-border
Compliant with Hong Kong PDPO and mainland PIPL; a “two-sites, three-centres” architecture keeps data physically isolated and non-cross-border. Positioned as a software tool provider, with professional judgement reviewed by licensed professionals.
Compliance-first · Risk-controlled · Shared value
We actively manage regulatory risk across three layers: product positioning, employment language, and data architecture.
Professional-service licensing
Modules such as “Accounting” touch invoice processing, tax-filing prep, and reconciliation, which in either jurisdiction could be deemed “accounting services” or “tax agency”; outputting professional services as software risks regulatory arbitrage.
Positioned as a “software tool provider”; key professional judgement is reviewed by licensed professionals (e.g. CPAs).
Labour law & displacement
Replacing standardized roles at scale can trigger union resistance, layoff-compliance disputes, or “digital divide” reputational risk.
Emphasize “AI handles the repetitive; people level up to strategy and review”; external language strictly avoids “layoff” / “replace”.
Cross-border data transfer
Mainland China’s data-export security rules require a security assessment for important data leaving the country.
Where clients don’t use private deployment, a “two-sites, three-centres” architecture serves international clients from the HK node and mainland clients from the mainland node — physically isolated, non-cross-border.