Security
Last updated: September 2, 2026
Clarify is built with security and privacy as foundational principles. This page outlines how we protect your data — the controls, certifications, and practices behind the platform.
Data protection and infrastructure
Where your data lives
All customer data is hosted on enterprise-grade AWS infrastructure within the United States.
Multi-layered security
- Data is encrypted in transit and at rest
- Backups: Fully encrypted backups and annual recovery testing
Regional hosting
Currently US-only, with EU hosting planned.
Access controls and internal safeguards
Only essential engineering and support staff have production access. Every access event is logged and monitored.
How we control internal access:
- Multi-factor authentication required for all production systems
- Role-based access controls
- Audit logging for all administrative actions
Compliance certifications
SOC 2
Clarify is SOC 2 Type 2 compliant, validating our security controls through independent auditing to ensure effective protection of customer data.
HIPAA
Clarify supports HIPAA compliance. A Business Associate Agreement (BAA) is available for customers on our Growth plan and above.
GDPR
Clarify acts as a data processor for your customer data. A Data Processing Agreement (DPA) with Standard Contractual Clauses is available for customers on our Growth plan and above.
Product security features
Enterprise authentication
- Single Sign-On (SSO) and SAML.
- Contact us for SCIM support.
Security testing and monitoring
Continuous security validation
- External penetration testing: Annually by qualified third-party firms
- Vulnerability scanning: Vulnerabilities are logged and tracked across all platforms
- Secret scanning: automated scanning to prevent secrets in code
Resources
System status
Security contact
- General security questions: security@clarify.ai
Trust center
We'll notify customers of any material changes to these policies.