Skip to content

Security

Security, without the theatre.

No badge walls, no vague claims. Here is exactly how Clarion handles your data today — and what is on the roadmap, labelled as roadmap.

In force

PIPEDA-aligned by design

Clarion is built around PIPEDA's principles: collect the minimum, use it only for the stated purpose, and keep workspace data under your control. Most of what we ingest is public record; what you add — topics, clients, notes — stays yours.

In force

Encryption in transit and at rest

All traffic is encrypted with TLS, and data is encrypted at rest on the managed cloud infrastructure that runs Clarion. We don't operate our own servers — we build on providers whose physical and network security operates at a scale no early-stage company could match alone.

In force

Hardened web delivery

Every response carries strict transport security (HSTS), content-type, framing, referrer, and permissions policies, plus a Content-Security-Policy — enforced across both our public site and the signed-in application, not report-only. Standard protections against transport downgrade, clickjacking, and content injection, on by default.

In force

Workspace isolation, RBAC, audit logs

Every query is scoped to your workspace. Role-based access control separates owners, admins, and members, and an append-only audit log records sensitive actions — entries can be added, never edited or deleted.

In force

Data residency

Our application tier and our primary database both currently run in the United States (US-East) on managed infrastructure, encrypted in transit and at rest — neither Vercel nor our database provider offers a Canadian region today, so we use the nearest available option and disclose that here rather than imply otherwise. Most of what we ingest is public record. For the personal data you add, we contractually require comparable protection consistent with PIPEDA's accountability principle, and we provide a transfer-impact assessment and a data processing agreement (DPA) on request. A Canadian region for both is on our roadmap.

On the roadmap

SOC 2 Type I: on the roadmap

We are not SOC 2 certified today, and we won't pretend otherwise. A Type I audit is planned as the platform grows, and this page will change the day that changes.

In force

Responsible disclosure

Found a vulnerability? Email us — we read every report and credit researchers who help us, no NDA required to tell us something is broken.

security@withclarion.com

Sub-processors

Every external provider that can touch your data, drawn directly from what is actually wired into the product today — not a boilerplate list. Most are key-optional: the platform runs without them and upgrades automatically the moment a key is configured. See our Privacy Policy for the full legal detail.

ProviderPurposeStatusRegion
VercelHosts and serves both the marketing site and the Clarion application — builds, edge network, and scheduled jobs.Always in use — required infrastructure.United States (US-East), plus a global edge network.
NeonPrimary Postgres database — workspace, account, and billing records.Production only — local development uses an embedded database (PGlite) with no third party involved.United States (US-East).
RailwayHosts the scheduled data-ingestion and AI-matching pipeline that populates your workspace.Production only — required infrastructure once the pipeline is deployed.United States — Railway does not offer Canadian region pinning today.
ClerkAuthentication and identity — your name, email, and sign-in sessions.Production only — local development runs Clerk in keyless mode, which provisions a temporary Clerk application over the network; no customer account data is involved locally.United States.
StripePayment processing for paid plans. Stripe collects and holds full card data directly — we never see or store complete card numbers.Key-optional — engaged only when billing keys are configured; without them the billing page runs in a degraded, non-charging state.United States.
Google (Gemini API)Primary AI provider — assistant answers, document summaries, and match grading over your workspace content.Key-optional — this is the PRIMARY AI key. Without it, the assistant runs retrieval-only and grading falls back to a lexical method; no workspace content is sent anywhere for this purpose.United States.
Anthropic (Claude API)Operator-invoked alternate AI provider — a manual break-glass switch, never an automatic fallback from Google.Key-optional — off by default; engaged only when an operator explicitly sets CLARION_LLM_PROVIDER=anthropic.United States.
Voyage AITurns search queries and workspace content into embeddings that power semantic and hybrid search. Voyage AI is a MongoDB company (acquired February 2025).Key-optional — without it, search falls back to lexical-only ranking (the semantic re-rank is skipped) and nothing is sent to Voyage.United States.
OpenAIPaid GEO add-on only — measures how your configured brand/topic watchlist appears inside OpenAI's search-grounded answers.Key-optional, add-on only — off unless the GEO add-on is purchased and a key is configured.United States.
PerplexityPaid GEO add-on only — the same brand/topic visibility measurement, via Perplexity's search-grounded API.Key-optional, add-on only — off unless the GEO add-on is purchased and a key is configured.United States.
ResendDelivers transactional and alert email — digests, notifications, and account messages.Key-optional — without it, email delivery is skipped and recorded honestly; Slack webhook delivery, if configured, keeps working.United States.
Cloudflare R2Object storage for a durability sidecar of ingested public-source documents, and for archived report exports.Key-optional — without R2 keys, uploads are skipped; nothing else in the product depends on it.Global object storage (Cloudflare network).
SentryServer-side error tracking for the application, to find and fix bugs.Key-optional — with no Sentry key configured, this is entirely inert. When on, we strip personal data before an event is sent.Depends on the Sentry organization's region configuration (not pinned in our code).
SlackIf a workspace configures its own Slack incoming webhook, we post alert and match content there.Customer-configured, opt-in per workspace — this sends data to a Slack workspace you control, not one under Clarion's control.Determined by your own Slack workspace.
Cloudflare Web AnalyticsCookieless aggregate traffic and Core Web Vitals — on both the marketing site and the signed-in product app. Deliberately used instead of a session-replay tool inside the app because it captures no PII.Key-optional, cookieless — runs for every visitor without a consent prompt because it collects no personal data.Cloudflare global network.

Marketing site only

These do not touch workspace or account data — they are visitor-analytics and anti-spam tools on the public marketing site. The two analytics trackers load only after an explicit opt-in; the anti-spam challenge (Cloudflare Turnstile) runs without one and collects no analytics of its own.

ProviderPurposeStatusRegion
Google Analytics 4Aggregate traffic analytics on the marketing site.Opt-in, key-optional — dormant unless configured, and loads only after you click "Accept" on the cookie banner.United States.
Microsoft ClarityHeatmaps and session replay to understand how visitors use the marketing site.Opt-in, key-optional — same consent gate as Google Analytics 4; never loads before you accept.United States.
Cloudflare TurnstileAnti-spam challenge on the marketing site's newsletter sign-up form, verified server-side.Key-optional — dormant unless a site key is configured.Cloudflare global network.

Not listed: Healthchecks.io, an operator-only uptime ping with no payload — it never receives product or personal data.

Security questionnaire or procurement requirements? Write to us:

hello@withclarion.com