Trust Center
A compliance company should show its own work.
This page describes how ClearCompliance protects its own systems and client information — the same standard we hold our clients to.
Security overview.
Access control
MFA is required on all company systems. Access follows least privilege with role-based permissions, and access is reviewed on a recurring schedule and removed at offboarding.
Encryption
Client data is encrypted in transit using TLS and at rest using the storage encryption of our vetted cloud providers.
Client data handling
We minimize what we collect, prohibit PHI transfer to us unless necessary and contracted, and follow a documented retention schedule with secure deletion.
Workforce
Personnel complete security-awareness and HIPAA training and are bound by confidentiality obligations appropriate to their roles.
Incident response
We maintain our own incident response procedures, an incident log, and defined client notification commitments in our agreements.
Vendor management
Our own vendors are risk-assessed, and agreements — including DPAs and BAAs where appropriate — are tracked with renewal dates.
Certifications and attestation reports are listed here only when actually earned. None are currently published — we hold ourselves to the same no-unearned-badges rule we recommend to clients.
Privacy and disclosure.
Privacy overview
Our privacy notice describes what we collect through this website and our services, why, and your choices — including consent-based marketing and data-subject requests via info@clearcompliance.ai.
Responsible disclosure
Found a vulnerability in our systems? Report it to info@clearcompliance.ai. We acknowledge reports promptly, do not pursue good-faith researchers, and credit fixes where wanted.
Service status
Client workspace availability notices are communicated directly to active clients through the shared project channel.
BAA and DPA availability
We sign BAAs with clients where our role requires one, and offer a data-processing addendum on request. Both are available through the document request below.
Subprocessors.
Third parties that may process client information as part of delivering our services.
The current subprocessor list — covering hosting, productivity, and workspace tooling — is provided as a document through the request form below, so recipients always receive the current version with dates and purposes. Material changes are communicated to active clients in advance per our agreements.