Trust · Security

Built to hold other people's secrets

Verification data is some of the most sensitive data a company handles: registry records, ownership structures, identity documents, watchlist hits. Security is not a feature we added to clearbound — it is the constraint everything else was designed around.

SOC 2Type II attested, renewed annually
ISO 27001Certified ISMS across the platform
AES-256Encryption at rest, TLS 1.2+ in transit
99.99%Trailing 12-month API availability

Controls

The controls that matter, on by default

Nothing here is an enterprise add-on. Every account gets the same encryption, isolation, and audit surface from the first sandbox call.

Encryption everywhere

All traffic is TLS 1.2+ with modern ciphers; plain HTTP is rejected at the edge. Data at rest is encrypted with AES-256, with keys managed in a dedicated KMS and rotated automatically. Documents get an additional per-object envelope key.

Hard tenant isolation

Every query in the platform is scoped by tenant at the data layer, not in application code. Sandbox and live environments are fully separated — a verification created in one is never visible in the other, and test keys can never reach live data.

Least-privilege access

Production access requires SSO with hardware-key MFA, is granted just-in-time against a ticket, and expires automatically. No standing access to customer data exists — for engineers, support, or anyone else.

Complete audit trail

Every read and write of verification data — by your team, your API keys, or ours — lands in an append-only audit log you can query from the dashboard and export to your SIEM. Reviews and alert acknowledgements are recorded with who, what, and when.

Retention you control

Default retention keeps completed verifications for the regulatory minimum in your jurisdiction and original documents for 90 days. You can extend or shorten both per policy, and deletion requests purge primary stores within 24 hours and backups within 30 days.

Continuously tested

An independent firm runs a full penetration test twice a year; findings and remediation timelines are available under NDA. Between tests we run continuous dependency scanning, static analysis on every commit, and a private bug-bounty program.

Data handling

We store the decision, not a data lake

clearbound is deliberately a system of record for decisions, not a warehouse of everything we can collect. We keep what makes a verification auditable and defensible — and nothing else.

  • Registry and watchlist sources are queried live; raw source dumps are never retained.
  • Document images are held only through review plus your retention window, then purged.
  • Beneficial-owner personal data is minimized to what the UBO determination requires.
  • Data stays in your selected region (US or EU); cross-region replication is opt-in only.
  • Subprocessors are listed publicly, vetted annually, and bound by equivalent terms.
How we handle personal data →
Data lifecycle · vrf_8c21f0a4e7
Decision record · retained per policy encrypted
Documents · purge in 82 days scheduled
Raw registry responses not retained
Audit log · append-only immutable

Responsible disclosure

Found something? Tell us first.

We take reports from outside researchers seriously and respond to every one. If you believe you have found a vulnerability in clearbound, email security@clearbound.xyz — PGP key and safe-harbor terms are included in our security.txt.

  • Acknowledgement within one business day, triage within three.
  • Good-faith research under our policy will never trigger legal action.
  • Qualifying reports are eligible for bounties through our private program.
  • We notify affected customers of any confirmed incident within 72 hours, with a full post-mortem to follow.
Contact the team →
security.txt
Contact: mailto:security@clearbound.xyz
Encryption: https://clearbound.xyz/pgp.asc
Preferred-Languages: en
Policy: https://clearbound.xyz/security
# Safe harbor applies to good-faith research

Verify businesses without taking on their risk

Start in the sandbox — same encryption, same isolation, no card required. Go live when your review is done.