Audit underway
SOC 2 Type II
SOC 2 Type II audit underway. Until then, our security controls inherit from SOC 2 Type II–audited infrastructure (AWS). Full SOC 2 readiness report available under NDA.
Trust
Enterprise-grade security built for financial data. Every layer designed to protect sensitive portfolio information.
What you can verify
Click any metric to see its definition, the accounts it's mapped from, and the statement report lines those accounts came from. No black-box formulas, no obscured calculations. Individual transactions stay in your accounting system: Clarifi imports the report totals, not a copy of your ledger. The traceability IS the audit trail; you don't have to take our word for it.
Data encrypted at rest (AES-256) on the underlying database, and in transit via TLS 1.3.
Least-privilege defaults. Founders, investors, and admins see only what their role scopes.
Significant actions on grants, exports, and role changes are recorded to an append-only audit table. Only server-side functions can insert a row, and the application is granted no update or delete on them.
SOC 2 Type II audit underway. Until then, our security controls inherit from SOC 2 Type II–audited infrastructure (AWS). Full SOC 2 readiness report available under NDA.
Time-based one-time passwords (TOTP) from an authenticator app. Every account can enroll from its own security settings, and step-up verification is required before investor connections open. All accounts sign in with email.
Row-level security policies scope data per organization on the underlying Postgres layer.
Founders control three axes: which metrics are shared, which investors see them, and how fresh the investor view is: live, by snapshot, or paused.
Documented incident response plan. Specific monitoring and SLA commitments are published in your service agreement.
The Data Bridge
Step 1
Founder
Publishes a grant scoped per investor.
Step 2
Grant
Time-bounded · revocable · scope-limited · live or snapshot.
Step 3
VC firm
Reads within the grant scope. Export follows scope.
Step 4
Audit log
Grant lifecycle events recorded: published, changed, revoked.
Clarifi records what you publish and change, not when an investor looks. There is no read event, so the log cannot tell you a number was opened.
Financial data requires the highest standards of protection. Our infrastructure meets institutional requirements from day one.
Audit underway
SOC 2 Type II
SOC 2 Type II audit underway. Until then, our security controls inherit from SOC 2 Type II–audited infrastructure (AWS). Full SOC 2 readiness report available under NDA.
Rights requests honored
GDPR
Clarifi processes Customer Data as a processor. We honor access, correction, deletion, objection, restriction, and portability requests. Export a full archive of your workspace yourself from the Export All Data card in Settings; send anything else to contact@clarifi.vc. The Privacy Policy sets out how we verify and answer a request.
AWS
Data Hosting
Runs on SOC 2 Type II–audited AWS infrastructure.
Walk-through
Our team is happy to walk through our security practices, share our SOC 2 readiness report, and discuss any custom requirements.
Aggregated portfolio metrics, normalization insights, and operational best practices. One email per month. Unsubscribe anytime.