Encryption
In-transit and at-rest
End-to-end confidentiality from your browser to our database. Briefs are delivered over encrypted channels; storage is encrypted at the provider layer.
- HTTPS / TLS 1.2+ for all client-to-server traffic (Render-managed certificate)
- Database encryption at rest via Neon PostgreSQL with provider-managed encryption
- Pending legal review [Placeholder] Customer-managed KMS (AWS KMS / GCP Cloud KMS) is not currently provisioned — we rely on Neon-managed keys
- Pending legal review [Placeholder] KMS key rotation cadence to be confirmed by ops
- Pending legal review [Placeholder] BYOK (bring-your-own-key) support is not currently offered
Access Control
Who can see your brief
Today Clearstake delivers briefs via email and a one-time status check link. There is no end-user application login; broader identity and audit controls are planned.
- Pending legal review [Placeholder] Enterprise SSO (SAML / OIDC) is not currently supported — delivered via single-tenant identity only
- Pending legal review [Placeholder] Role-based access control (RBAC) within an end-user dashboard is not yet implemented
- Pending legal review [Placeholder] Granular per-user audit logs of brief views are not currently emitted
- Internal RBAC — Clearstake staff access is gated by role on internal tooling (separate from the public site)
- One-time access codes — Briefs are tied to a per-request status link that reveals results only after code entry
Compliance
Certifications & data handling
Clearstake is a single-service SaaS in active growth. Several formal certifications are still in flight; this section flags each claim that has not yet been independently attested.
- Pending legal review [Placeholder] SOC 2 Status — Not yet certified. Type II audit has not yet started. We do not currently claim SOC 2 conformance.
- Pending legal review [Placeholder] GDPR posture — Data subject access and deletion workflows are not yet documented for customer use; a formal DPA is not currently offered self-serve. Email-based request handling is in place.
- Pending legal review [Placeholder] Data residency — Application data is hosted on Neon; specific region pinning (US-only / EU-only) is not currently configurable.
- Pending legal review [Placeholder] Privacy documentation — A formal privacy policy is not yet published at a dedicated URL.
- Email-only delivery — Briefs are delivered to a single recipient email provided by the requester; no broad distribution channel increases exposure.