Skip to main content

Trust

Security & Compliance

Enterprise-grade security built for financial data. Every layer designed to protect sensitive portfolio information.

What you can verify

Every KPI on Clarifi traces back to the accounts it was built from.

Click any metric to see its definition, the accounts it's mapped from, and the statement report lines those accounts came from. No black-box formulas, no obscured calculations. Individual transactions stay in your accounting system: Clarifi imports the report totals, not a copy of your ledger. The traceability IS the audit trail; you don't have to take our word for it.

Eight controls

Encryption

Data encrypted at rest (AES-256) on the underlying database, and in transit via TLS 1.3.

Role-Based Access

Least-privilege defaults. Founders, investors, and admins see only what their role scopes.

Audit Logging

Significant actions on grants, exports, and role changes are recorded to an append-only audit table. Only server-side functions can insert a row, and the application is granted no update or delete on them.

SOC 2 Type II

SOC 2 Type II audit underway. Until then, our security controls inherit from SOC 2 Type II–audited infrastructure (AWS). Full SOC 2 readiness report available under NDA.

Multi-Factor Authentication

Time-based one-time passwords (TOTP) from an authenticator app. Every account can enroll from its own security settings, and step-up verification is required before investor connections open. All accounts sign in with email.

Tenant Isolation

Row-level security policies scope data per organization on the underlying Postgres layer.

Granular Permissions

Founders control three axes: which metrics are shared, which investors see them, and how fresh the investor view is: live, by snapshot, or paused.

Incident Response

Documented incident response plan. Specific monitoring and SLA commitments are published in your service agreement.

The Data Bridge

Founders publish. Investors read scoped grants. Lifecycle is logged.

Clarifi records what you publish and change, not when an investor looks. There is no read event, so the log cannot tell you a number was opened.

Built for Regulated Industries

Financial data requires the highest standards of protection. Our infrastructure meets institutional requirements from day one.

Audit underway

SOC 2 Type II

SOC 2 Type II audit underway. Until then, our security controls inherit from SOC 2 Type II–audited infrastructure (AWS). Full SOC 2 readiness report available under NDA.

Rights requests honored

GDPR

Clarifi processes Customer Data as a processor. We honor access, correction, deletion, objection, restriction, and portability requests. Export a full archive of your workspace yourself from the Export All Data card in Settings; send anything else to contact@clarifi.vc. The Privacy Policy sets out how we verify and answer a request.

AWS

Data Hosting

Runs on SOC 2 Type II–audited AWS infrastructure.

Walk-through

Walk through your security model with us

Our team is happy to walk through our security practices, share our SOC 2 readiness report, and discuss any custom requirements.

The Monthly Portfolio Benchmark

Aggregated portfolio metrics, normalization insights, and operational best practices. One email per month. Unsubscribe anytime.