Security & Trust

How we handle your deal intelligence

Pre-deal diligence briefs sit at the intersection of confidential M&A data and high-stakes decision-making. This page documents how Clearstake protects it.

Encryption

In-transit and at-rest

End-to-end confidentiality from your browser to our database. Briefs are delivered over encrypted channels; storage is encrypted at the provider layer.

  • HTTPS / TLS 1.2+ for all client-to-server traffic (Render-managed certificate)
  • Database encryption at rest via Neon PostgreSQL with provider-managed encryption
  • Pending legal review [Placeholder] Customer-managed KMS (AWS KMS / GCP Cloud KMS) is not currently provisioned — we rely on Neon-managed keys
  • Pending legal review [Placeholder] KMS key rotation cadence to be confirmed by ops
  • Pending legal review [Placeholder] BYOK (bring-your-own-key) support is not currently offered

Access Control

Who can see your brief

Today Clearstake delivers briefs via email and a one-time status check link. There is no end-user application login; broader identity and audit controls are planned.

  • Pending legal review [Placeholder] Enterprise SSO (SAML / OIDC) is not currently supported — delivered via single-tenant identity only
  • Pending legal review [Placeholder] Role-based access control (RBAC) within an end-user dashboard is not yet implemented
  • Pending legal review [Placeholder] Granular per-user audit logs of brief views are not currently emitted
  • Internal RBAC — Clearstake staff access is gated by role on internal tooling (separate from the public site)
  • One-time access codes — Briefs are tied to a per-request status link that reveals results only after code entry

Compliance

Certifications & data handling

Clearstake is a single-service SaaS in active growth. Several formal certifications are still in flight; this section flags each claim that has not yet been independently attested.

  • Pending legal review [Placeholder] SOC 2 Status — Not yet certified. Type II audit has not yet started. We do not currently claim SOC 2 conformance.
  • Pending legal review [Placeholder] GDPR posture — Data subject access and deletion workflows are not yet documented for customer use; a formal DPA is not currently offered self-serve. Email-based request handling is in place.
  • Pending legal review [Placeholder] Data residency — Application data is hosted on Neon; specific region pinning (US-only / EU-only) is not currently configurable.
  • Pending legal review [Placeholder] Privacy documentation — A formal privacy policy is not yet published at a dedicated URL.
  • Email-only delivery — Briefs are delivered to a single recipient email provided by the requester; no broad distribution channel increases exposure.
Pending legal review

Procurement, legal, or security teams with questionnaire requests: email security@clearstake.com [Placeholder — security contact email pending legal confirmation] and we will route to the appropriate reviewer.