Uncompromising security. Absolute peace of mind.
At ClearMash, security isn’t just a feature - it’s a foundation. Understanding that privacy and data security are paramount, we are dedicated to delivering a robust, reliable environment that secures both your data and ours.
A Brain influences employee decisions, customer answers and AI-agent behavior. That makes it an asset to secure and a system to govern, and securing it is not the same work as governing it.
An asset that shapes decisions has to be governed like one.
Certified to
Trusted by knowledge-intensive organizations
Automotive
Hospitality
Financial Services
Telecom
Automotive
Education
Software
Financial Services
Financial Services
Retail
Automotive
Education
Insurance
Independently examined, and examined again
Certification is a floor rather than a finish. It says an independent party examined how the work is done and will examine it again.
A certificate does not replace your own review, and we would rather help you run one than argue that it makes one unnecessary. Each certification carries its own scope, stated on the certificate itself, so what we send you is the certificate and the scope statement that belongs to it.
-
Information Security
SOC 2 Type 2
Information security standard.
What it coversAn independent examination covering a period of operation rather than a single day. Type 2 is the distinction that matters to a reviewer: it reports whether the controls operated, not only whether they were designed.
-
Corporate Security
ISO/IEC 27001
The most comprehensive information security standard for managing information security (ISMS).
What it coversThe management-system standard for information security: how risk is assessed, which controls are selected, how they are operated, and how the arrangement is audited and re-audited rather than asserted once.
-
Cloud Security
ISO/IEC 27017
What it coversCloud-specific controls layered on 27001, including the part enterprise reviewers ask about first: which responsibilities sit with the provider, which sit with the customer, and where the line between them runs.
-
Cloud Privacy
ISO/IEC 27018
What it coversThe code of practice for handling personal information in a public cloud: how it may be used, who it may be disclosed to, and what becomes of it at the end of the relationship.
-
Software Quality
ISO/IEC 90003
The most comprehensive quality standard for software organizations.
What it coversQuality management for software engineering: how a product is specified, built, reviewed, tested and maintained. A large share of security defects are prevented at that stage rather than at the perimeter.
Certificates, scope statements and the current security documentation pack are available on request, and your security team is welcome to review them as part of an evaluation.
GDPR, and what we have put in writing
GDPR is law rather than a certification scheme, so there is no GDPR certificate for anyone to hold. What there is, is a contract. Our data processing addendum carries a part written for the EU and UK GDPR, in force wherever the personal data we process for you falls under them. In it your organization is the controller and ClearMash is the processor, and the duties a processor owes under the regulation are set out as terms you can hold us to.
The architecture points the same way. A Brain is deliberately not a second copy of your customer records, so there is less personal data inside it to govern in the first place, and the processing terms set out what may be done with what there is.
- Personal data processed only on your documented instructions, and only for the purposes you set.
- Personal data processed in the European Economic Area, in a territory covered by a European Commission adequacy decision, or under the transfer safeguards the addendum names, such as the model clauses.
- Confidentiality undertakings from the people authorized to process it.
- Notice of a personal data breach without undue delay, and in any event within 48 hours of becoming aware of it.
- A data subject request that arrives with us passed to you, with its details, within three business days.
- Sub-processors published and reviewed every year, with at least ten business days’ notice before one is added or replaced, and your right to object on reasoned grounds.
- Audits and inspections arranged within 21 days of your written request, and help with privacy impact assessments and prior consultation.
- Personal data returned or deleted within ten business days of your request, with written confirmation.
The addendum names a Data Protection Officer as the point of contact for all of it, reachable at dpo@clearmash.com. Whether a given deployment meets your own obligations is your privacy team’s call rather than ours, which is why the document is published here in full and this list points at it rather than standing in for it.
Read the data processing addendum, including the EU and UK GDPR part
Keeping your data secure
What we did, who to ask, and where European data can be kept.
We have worked with experts, information security professionals, and legal counsel to ensure that both our product and our Terms of Use meet the required security standards for organizations of all sizes, and we will continue doing so in the future. As part of this effort, we reviewed our security procedures, obtained ISO 27001, ISO 27017, ISO 27018, ISO 90003, and SOC 2 Type 2 certifications, updated our Terms of Use, verified that our cloud infrastructure providers are suitable for large organizations, updated relevant procedures, and implemented security tools. We are committed to monitoring regulatory and legal guidelines to ensure our solution continues to meet all necessary requirements.
- Data Protection Officer
- dpo@clearmash.com
- European data residency
- European customers can request that their data remain exclusively within Europe by contacting our support team.
- More information
- For more information, contact the support team.
Information security capabilities
What is built into the solution, and what the cloud infrastructure underneath it contributes.
Information security capabilities embedded in our solution
- All data is encrypted in transit (HTTPS)
- All disks are encrypted at the hardware level
- Sensitive data is additionally secured with logical encryption
- MFA mechanism for logging
- Option to integrate external authentication providers (Azure AD, OKTA)
- Detailed information security logs are maintained
- Brute force protection
- Configurable password policies for different groups
- Automatic logout
- Comprehensive role and permissions management
- Complete separation of data for different customers
- Continuous environment monitoring
- EDR
- Bot protection
- OWASP 10 protections
And more…
Our information security capabilities as part of our cloud infrastructure
- DDoS protection on network-level and application-level
- WAF protection
- Advanced firewalls
- Antivirus protection
- Continuous vulnerability monitoring
- Strict access policy
- Highly secure cloud infrastructure
- Separate database for each customer
- Separation of responsibilities and access
- Strict backup and recovery policy
- Security, privacy, spam, and other alerts
- Frequent SSL checks
And more…
Protecting the Brain
Keeping the knowledge confidential, and keeping it honest.
The knowledge in the Brain is organizational intellectual property: what you offer, what you permit, how you work and how your best people make decisions. It is protected as material of that value, in transit and at rest, with complete separation of data between customers and a separate database for each of them. Where an organization has to be isolated rather than separated, a separated environment - single-tenancy deployment, your Brain in an environment of its own - is available as an Enterprise add-on.
Integrity is part of that protection: knowing that what is published is what was approved, that changes are attributable, and that an earlier version can be produced when someone asks what applied at the time.
Separated environments
Enterprise add-on
A single-tenancy deployment: your Brain in an environment of its own, for organizations required to be isolated rather than separated. Separation of data between customers, and a database per customer, hold at every level.
Protected in transit and at rest
Organizational knowledge is treated as material with commercial value, because that is what it is.
Attributable change
Who changed what the organization says, and when, held as part of the knowledge rather than beside it.
Approval before publication
Nothing reaches an employee, a customer or an AI agent until the knowledge owner accountable for it approves it.
A retrievable earlier version
What was published on a given date can be produced later, which is usually when someone needs it.
Controlling access
Who may see this, and which AI agent may act on it. The question about the AI agent is newer and harder.
People and AI agents receive what they are authorized to receive, under your organization’s own rules. Role, department, region and audience determine what is visible, and an AI agent acting for a user is bound by the same limits as the user.
This matters more with AI than it did without it. An AI agent that can reach everything will eventually reveal something to somebody who should not have seen it, and it will do so fluently and at scale.
An AI agent is treated as a subject with an identity, not as a channel with a key. It acts for an employee, a customer or a service, it inherits that identity’s limits, and it stops where that identity stops. An agent permitted to reach everything is a new kind of exposure with a very old kind of consequence.
Role, department, region
The dimensions your organization already governs, now applied to knowledge as well as to records.
Audience
Customer, employee, partner and AI agent views of one governed meaning, each shaped for what that audience may act on.
AI agents inherit limits
An AI agent acting for an employee, a customer or a service reaches only what that identity can reach.
Identity from your provider
Users, services and AI agents authenticate through the identity provider you already run, with the option to integrate Azure AD or OKTA.
Visible authorization
What an audience was entitled to see is a property of the knowledge, so it can be reviewed rather than reconstructed.
Protecting enterprise information
The data boundary is a security property before it is an architectural one.
ClearMash Brain is deliberately not the permanent home of your customer records, transactions, orders, claims or employee data. Those stay in the systems built to manage them, with the controls and obligations already established around them.
Where current information is needed to determine what applies, it is used for that purpose. The boundary is a security property as much as an architectural one: a system that never becomes a copy of your enterprise data gives an attacker far less to take.
Copies are where obligations multiply. Another place personal data can be found. Another retention schedule to defend. Another system to include in a deletion request. Another export to explain to a regulator. A copy of everything carries all of that twice.
It is a contractual matter as well as an architectural one. The data processing addendum and the sub-processor list in our legal section set the boundary out in terms your procurement and privacy teams can review.
Systems of record keep their records
Customers, transactions, orders, claims and employee data stay where they are already governed.
Current facts are used, not accumulated
A fact is drawn on to decide what applies, which is not the same as holding a copy of it.
Fewer obligations inherited
A system that is not a second copy of your enterprise data does not create a second set of duties around it.
Separated by customer
Complete separation of data for different customers, with a separate database for each customer.
Written into the contract
The processing terms and the sub-processor list describe the boundary, not only the architecture.
Responsible AI and human control
AI can help build the Brain. It does not decide what your organization says.
AI may assist the Brain. Your organization remains in control of what it knows and how it works. Knowledge owners approve what is published, and nothing reaches employees, customers or AI agents on the strength of a model’s suggestion alone.
The same discipline applies to what AI agents are permitted to do. Defined skills, explicit boundaries, and a clear point at which a case must reach an employee are part of the knowledge, not settings buried in a tool. An AI agent inherits the access limits of the identity it acts for, so it cannot become the route around an access rule.
Security documentation, on request
Everything a security, privacy or procurement review needs, sent to the people running the review.
- The certificate for each published certification, with the scope statement that belongs to it.
- The current security documentation pack covering how the platform is built, operated and protected.
- The data processing addendum and the current sub-processor list.
- A review of all of it with your security team as part of the evaluation.
Ask early. It is a shorter conversation during evaluation than at contract stage, and it usually changes what gets scoped.
What enterprise reviewers usually ask
Who can change what we say?
Who can change what the organization says, and is that change visible?
What applied on a given date?
Can we show what was published on a given date?
What can an AI agent reach?
Does an AI agent inherit the limits of the employee or customer it acts for?
Where does the data live?
Where does customer and personal data live, and what does the Brain hold about it?
What is in scope?
What is in scope for each certification you publish?
How do you handle a review?
What is your process when a customer’s security team wants to review the platform?
Contact our information security team
Have questions about information security? We’re here to help.
A question during evaluation is worth more to both of us than a finding after signature.
Get the security documentation pack
It covers how the platform is built, operated and protected. Our information security team answers your reviewers’ questions.
Prefer to start with the numbers? The impact estimator works them out