Trust Center

A compliance company should show its own work.

This page describes how ClearCompliance protects its own systems and client information — the same standard we hold our clients to.

Security overview.

Access control

MFA is required on all company systems. Access follows least privilege with role-based permissions, and access is reviewed on a recurring schedule and removed at offboarding.

Encryption

Client data is encrypted in transit using TLS and at rest using the storage encryption of our vetted cloud providers.

Client data handling

We minimize what we collect, prohibit PHI transfer to us unless necessary and contracted, and follow a documented retention schedule with secure deletion.

Workforce

Personnel complete security-awareness and HIPAA training and are bound by confidentiality obligations appropriate to their roles.

Incident response

We maintain our own incident response procedures, an incident log, and defined client notification commitments in our agreements.

Vendor management

Our own vendors are risk-assessed, and agreements — including DPAs and BAAs where appropriate — are tracked with renewal dates.

Certifications and attestation reports are listed here only when actually earned. None are currently published — we hold ourselves to the same no-unearned-badges rule we recommend to clients.

Privacy and disclosure.

Privacy overview

Our privacy notice describes what we collect through this website and our services, why, and your choices — including consent-based marketing and data-subject requests via info@clearcompliance.ai.

Responsible disclosure

Found a vulnerability in our systems? Report it to info@clearcompliance.ai. We acknowledge reports promptly, do not pursue good-faith researchers, and credit fixes where wanted.

Service status

Client workspace availability notices are communicated directly to active clients through the shared project channel.

BAA and DPA availability

We sign BAAs with clients where our role requires one, and offer a data-processing addendum on request. Both are available through the document request below.

Subprocessors.

Third parties that may process client information as part of delivering our services.

The current subprocessor list — covering hosting, productivity, and workspace tooling — is provided as a document through the request form below, so recipients always receive the current version with dates and purposes. Material changes are communicated to active clients in advance per our agreements.

Request a document.

Do not submit patient or health information.