Uncompromising security. Absolute peace of mind.

At ClearMash, security isn’t just a feature - it’s a foundation. Understanding that privacy and data security are paramount, we are dedicated to delivering a robust, reliable environment that secures both your data and ours.

A Brain influences employee decisions, customer answers and AI-agent behavior. That makes it an asset to secure and a system to govern, and securing it is not the same work as governing it.

An asset that shapes decisions has to be governed like one.

Certified to

  • SOC 2 Type 2
  • ISO/IEC 27001
  • ISO/IEC 27017
  • ISO/IEC 27018
  • ISO/IEC 90003

Trusted by knowledge-intensive organizations

Independently examined, and examined again

Certification is a floor rather than a finish. It says an independent party examined how the work is done and will examine it again.

A certificate does not replace your own review, and we would rather help you run one than argue that it makes one unnecessary. Each certification carries its own scope, stated on the certificate itself, so what we send you is the certificate and the scope statement that belongs to it.

  • SOC 2 Type 2

    Information Security

    SOC 2 Type 2

    Information security standard.

    What it covers

    An independent examination covering a period of operation rather than a single day. Type 2 is the distinction that matters to a reviewer: it reports whether the controls operated, not only whether they were designed.

    Service organization controls, Trust Services CriteriaAICPA criteria, examined by an independent auditor

  • ISO/IEC 27001

    Corporate Security

    ISO/IEC 27001

    The most comprehensive information security standard for managing information security (ISMS).

    What it covers

    The management-system standard for information security: how risk is assessed, which controls are selected, how they are operated, and how the arrangement is audited and re-audited rather than asserted once.

    Information security management systemsISO and IEC

  • ISO/IEC 27017

    Cloud Security

    ISO/IEC 27017

    What it covers

    Cloud-specific controls layered on 27001, including the part enterprise reviewers ask about first: which responsibilities sit with the provider, which sit with the customer, and where the line between them runs.

    Information security controls for cloud servicesISO and IEC

  • ISO/IEC 27018

    Cloud Privacy

    ISO/IEC 27018

    What it covers

    The code of practice for handling personal information in a public cloud: how it may be used, who it may be disclosed to, and what becomes of it at the end of the relationship.

    Protection of personally identifiable information in public cloudsISO and IEC

  • ISO/IEC 90003

    Software Quality

    ISO/IEC 90003

    The most comprehensive quality standard for software organizations.

    What it covers

    Quality management for software engineering: how a product is specified, built, reviewed, tested and maintained. A large share of security defects are prevented at that stage rather than at the perimeter.

    Quality management applied to computer softwareISO and IEC

Certificates, scope statements and the current security documentation pack are available on request, and your security team is welcome to review them as part of an evaluation.

GDPR, and what we have put in writing

GDPR is law rather than a certification scheme, so there is no GDPR certificate for anyone to hold. What there is, is a contract. Our data processing addendum carries a part written for the EU and UK GDPR, in force wherever the personal data we process for you falls under them. In it your organization is the controller and ClearMash is the processor, and the duties a processor owes under the regulation are set out as terms you can hold us to.

The architecture points the same way. A Brain is deliberately not a second copy of your customer records, so there is less personal data inside it to govern in the first place, and the processing terms set out what may be done with what there is.

  • Personal data processed only on your documented instructions, and only for the purposes you set.
  • Personal data processed in the European Economic Area, in a territory covered by a European Commission adequacy decision, or under the transfer safeguards the addendum names, such as the model clauses.
  • Confidentiality undertakings from the people authorized to process it.
  • Notice of a personal data breach without undue delay, and in any event within 48 hours of becoming aware of it.
  • A data subject request that arrives with us passed to you, with its details, within three business days.
  • Sub-processors published and reviewed every year, with at least ten business days’ notice before one is added or replaced, and your right to object on reasoned grounds.
  • Audits and inspections arranged within 21 days of your written request, and help with privacy impact assessments and prior consultation.
  • Personal data returned or deleted within ten business days of your request, with written confirmation.

The addendum names a Data Protection Officer as the point of contact for all of it, reachable at dpo@clearmash.com. Whether a given deployment meets your own obligations is your privacy team’s call rather than ours, which is why the document is published here in full and this list points at it rather than standing in for it.

Read the data processing addendum, including the EU and UK GDPR part

Keeping your data secure

What we did, who to ask, and where European data can be kept.

We have worked with experts, information security professionals, and legal counsel to ensure that both our product and our Terms of Use meet the required security standards for organizations of all sizes, and we will continue doing so in the future. As part of this effort, we reviewed our security procedures, obtained ISO 27001, ISO 27017, ISO 27018, ISO 90003, and SOC 2 Type 2 certifications, updated our Terms of Use, verified that our cloud infrastructure providers are suitable for large organizations, updated relevant procedures, and implemented security tools. We are committed to monitoring regulatory and legal guidelines to ensure our solution continues to meet all necessary requirements.

Data Protection Officer
dpo@clearmash.com
European data residency
European customers can request that their data remain exclusively within Europe by contacting our support team.
More information
For more information, contact the support team.

Information security capabilities

What is built into the solution, and what the cloud infrastructure underneath it contributes.

Information security capabilities embedded in our solution

  • All data is encrypted in transit (HTTPS)
  • All disks are encrypted at the hardware level
  • Sensitive data is additionally secured with logical encryption
  • MFA mechanism for logging
  • Option to integrate external authentication providers (Azure AD, OKTA)
  • Detailed information security logs are maintained
  • Brute force protection
  • Configurable password policies for different groups
  • Automatic logout
  • Comprehensive role and permissions management
  • Complete separation of data for different customers
  • Continuous environment monitoring
  • EDR
  • Bot protection
  • OWASP 10 protections

And more…

Our information security capabilities as part of our cloud infrastructure

  • DDoS protection on network-level and application-level
  • WAF protection
  • Advanced firewalls
  • Antivirus protection
  • Continuous vulnerability monitoring
  • Strict access policy
  • Highly secure cloud infrastructure
  • Separate database for each customer
  • Separation of responsibilities and access
  • Strict backup and recovery policy
  • Security, privacy, spam, and other alerts
  • Frequent SSL checks

And more…

Protecting the Brain

Keeping the knowledge confidential, and keeping it honest.

The knowledge in the Brain is organizational intellectual property: what you offer, what you permit, how you work and how your best people make decisions. It is protected as material of that value, in transit and at rest, with complete separation of data between customers and a separate database for each of them. Where an organization has to be isolated rather than separated, a separated environment - single-tenancy deployment, your Brain in an environment of its own - is available as an Enterprise add-on.

Integrity is part of that protection: knowing that what is published is what was approved, that changes are attributable, and that an earlier version can be produced when someone asks what applied at the time.

  • Separated environments

    Enterprise add-on

    A single-tenancy deployment: your Brain in an environment of its own, for organizations required to be isolated rather than separated. Separation of data between customers, and a database per customer, hold at every level.

  • Protected in transit and at rest

    Organizational knowledge is treated as material with commercial value, because that is what it is.

  • Attributable change

    Who changed what the organization says, and when, held as part of the knowledge rather than beside it.

  • Approval before publication

    Nothing reaches an employee, a customer or an AI agent until the knowledge owner accountable for it approves it.

  • A retrievable earlier version

    What was published on a given date can be produced later, which is usually when someone needs it.

Controlling access

Who may see this, and which AI agent may act on it. The question about the AI agent is newer and harder.

People and AI agents receive what they are authorized to receive, under your organization’s own rules. Role, department, region and audience determine what is visible, and an AI agent acting for a user is bound by the same limits as the user.

This matters more with AI than it did without it. An AI agent that can reach everything will eventually reveal something to somebody who should not have seen it, and it will do so fluently and at scale.

An AI agent is treated as a subject with an identity, not as a channel with a key. It acts for an employee, a customer or a service, it inherits that identity’s limits, and it stops where that identity stops. An agent permitted to reach everything is a new kind of exposure with a very old kind of consequence.

  • Role, department, region

    The dimensions your organization already governs, now applied to knowledge as well as to records.

  • Audience

    Customer, employee, partner and AI agent views of one governed meaning, each shaped for what that audience may act on.

  • AI agents inherit limits

    An AI agent acting for an employee, a customer or a service reaches only what that identity can reach.

  • Identity from your provider

    Users, services and AI agents authenticate through the identity provider you already run, with the option to integrate Azure AD or OKTA.

  • Visible authorization

    What an audience was entitled to see is a property of the knowledge, so it can be reviewed rather than reconstructed.

Protecting enterprise information

The data boundary is a security property before it is an architectural one.

ClearMash Brain is deliberately not the permanent home of your customer records, transactions, orders, claims or employee data. Those stay in the systems built to manage them, with the controls and obligations already established around them.

Where current information is needed to determine what applies, it is used for that purpose. The boundary is a security property as much as an architectural one: a system that never becomes a copy of your enterprise data gives an attacker far less to take.

Copies are where obligations multiply. Another place personal data can be found. Another retention schedule to defend. Another system to include in a deletion request. Another export to explain to a regulator. A copy of everything carries all of that twice.

It is a contractual matter as well as an architectural one. The data processing addendum and the sub-processor list in our legal section set the boundary out in terms your procurement and privacy teams can review.

  • Systems of record keep their records

    Customers, transactions, orders, claims and employee data stay where they are already governed.

  • Current facts are used, not accumulated

    A fact is drawn on to decide what applies, which is not the same as holding a copy of it.

  • Fewer obligations inherited

    A system that is not a second copy of your enterprise data does not create a second set of duties around it.

  • Separated by customer

    Complete separation of data for different customers, with a separate database for each customer.

  • Written into the contract

    The processing terms and the sub-processor list describe the boundary, not only the architecture.

Responsible AI and human control

AI can help build the Brain. It does not decide what your organization says.

AI may assist the Brain. Your organization remains in control of what it knows and how it works. Knowledge owners approve what is published, and nothing reaches employees, customers or AI agents on the strength of a model’s suggestion alone.

The same discipline applies to what AI agents are permitted to do. Defined skills, explicit boundaries, and a clear point at which a case must reach an employee are part of the knowledge, not settings buried in a tool. An AI agent inherits the access limits of the identity it acts for, so it cannot become the route around an access rule.

The commitments in full, and how far the claim goes

Security documentation, on request

Everything a security, privacy or procurement review needs, sent to the people running the review.

  • The certificate for each published certification, with the scope statement that belongs to it.
  • The current security documentation pack covering how the platform is built, operated and protected.
  • The data processing addendum and the current sub-processor list.
  • A review of all of it with your security team as part of the evaluation.

Ask early. It is a shorter conversation during evaluation than at contract stage, and it usually changes what gets scoped.

What enterprise reviewers usually ask

  • Who can change what we say?

    Who can change what the organization says, and is that change visible?

  • What applied on a given date?

    Can we show what was published on a given date?

  • What can an AI agent reach?

    Does an AI agent inherit the limits of the employee or customer it acts for?

  • Where does the data live?

    Where does customer and personal data live, and what does the Brain hold about it?

  • What is in scope?

    What is in scope for each certification you publish?

  • How do you handle a review?

    What is your process when a customer’s security team wants to review the platform?

Contact our information security team

Have questions about information security? We’re here to help.

security@clearmash.com

A question during evaluation is worth more to both of us than a finding after signature.

Get the security documentation pack

It covers how the platform is built, operated and protected. Our information security team answers your reviewers’ questions.

Prefer to start with the numbers? The impact estimator works them out