Trust

Security.

How we protect your data, infrastructure, and the review process.

Encryption

At rest AES-256 encryption for all database storage and file storage.

In transit TLS 1.3 for all data transmitted between users and the platform, and between platform services.

Access control

Claract enforces role-based access control (RBAC) within each organization. Permissions are scoped per organization — no user can access data belonging to another organization. Row-level security policies in PostgreSQL enforce this at the database layer. RBAC roles: Admin, Reviewer, Observer. MFA enforced via YubiKey or Duo; SAML 2.0 supported.

Audit logs

Claract maintains an immutable audit log of who reviewed each packet and what changes were accepted. All review actions are logged with user identity and timestamp — notice submissions, finding acknowledgments, sign-off actions, and export events. Audit logs are retained for the lifetime of the account and are available to organization admins.

Data handling

Claract is hosted on Supabase, a managed database and storage platform built on PostgreSQL, distributed across multiple availability zones within the United States. Database backups are automated and encrypted.

Processing in AWS us-east-1 primary; us-west-2 disaster recovery. Active tenant data is purged after 24 months unless a Retention Flag is raised for legal reasons. Draft notices are retained on a 90-day rolling basis unless a customer policy requires a shorter period. Contract termination and customer deletion requests trigger permanent deletion per the configured workflow. Customer data is siloed per tenant — Claract does not use one customer's data to train another customer's model behavior.

Document security

Uploaded documents are stored with org-scoped bucket policies. Each organization's documents are isolated in storage paths accessible only to authenticated users within that organization. Document URLs are signed and time-limited.

Incident response

Incident response: 4-hour acknowledgement and 24-hour remediation target. Security reports go to security@claract.net. No auto-action. Human confirmation is mandatory for high-risk flags — Claract never sends, withholds, or alters a resident notice on its own.

Attestation

SOC 2 Type II achieved 18 February 2025; scope covers Customer Data & Compliance Evidence (Stage 3). ISO 27001 pending; submission Q3 2026. Claract does not claim HIPAA or PCI compliance. The controls described above are the practices Claract operates today.

Responsible disclosure

If you discover a security vulnerability in the Claract platform, report it responsibly to security@claract.net. We commit to acknowledging receipt within 48 hours, providing an initial assessment within 5 business days, and not pursuing legal action against researchers who act in good faith.

Security questions: security@claract.net