Security and privacy
How Clearly AI protects customer data across infrastructure, access, privacy, AI use, and vendor governance.
Clearly AI is built for security and risk teams that review sensitive product, system, and vendor information. Clearly AI protects customer data through isolated deployment options, encrypted storage, controlled access, AI data-use limits, and formal security operations.
Some enterprise deployment requirements can change the infrastructure or controls described here. Ask Clearly AI about requirements such as single-tenant infrastructure, private cloud, customer-managed keys, alternative data residency, or customer-provided model keys.
Infrastructure
Clearly AI uses Amazon Web Services (AWS) for hosted infrastructure. AWS secures the underlying cloud infrastructure, and Clearly AI secures the application, configuration, access controls, and customer data within that environment.
Hosted Clearly AI environments use managed AWS services for ingress, compute, storage, secrets, logging, and monitoring. Application services run in private networking paths, receive traffic through managed ingress protected by AWS WAF, and use role-based network rules to limit service-to-service traffic.
For deployment-specific details, see Deployment patterns.
Architecture overview
Clearly AI's hosted architecture follows this high-level flow:
- Users access Clearly AI through a tenant-specific HTTPS endpoint.
- Managed ingress terminates TLS and filters traffic through AWS WAF.
- Application services run as containerized workloads in private subnets.
- Application data, files, secrets, logs, and job metadata are stored in managed cloud services.
- Model provider calls use Clearly AI provider agreements or your configured provider keys.
- Integrations connect to approved third-party systems using organization or user-scoped credentials.
Data location
By default, hosted Clearly AI and customer data are stored in the United States in AWS. Clearly AI can support alternative data residency for certain enterprise deployments.
When an enterprise deployment uses alternative residency, some business contact data, such as employee name and business email address, may be processed outside that region for support, authentication, or debugging.
Tenant isolation
Clearly AI supports multi-tenant SaaS, single-tenant SaaS, and private cloud deployments.
Multi-tenant SaaS uses shared platform infrastructure with organization-level authentication, authorization, storage boundaries, and session controls to restrict each organization to its own data.
Single-tenant SaaS runs a dedicated Clearly AI environment for one customer, with separate network, compute, storage, secrets, logs, and monitoring resources.
Private cloud runs Clearly AI inside your cloud environment. This pattern is designed for organizations that need infrastructure, data residency, and network policy inside their own cloud boundary.
Data security
Connections to Clearly AI use TLS 1.2 or higher. Customer files and application data are encrypted at rest using managed cloud encryption.
Secrets and API keys are stored in managed secret stores. Saved model provider keys are encrypted at rest and are not displayed after saving.
Certain enterprise customers can use customer-managed encryption keys or bring their own model provider API keys. For model provider setup, see Model providers.
Access control
Clearly AI supports organization-level roles for owners, admins, and members. Admins can invite users, change roles, and remove access. For user management, see Members and roles.
Clearly AI supports SAML SSO, SCIM provisioning, allowed email domains, and two-factor authentication through the identity and authentication stack. For setup details, see SSO, SAML, and SCIM.
Clearly AI employees can access customer data only when required to provide a specific service. Employee access is limited to the minimum necessary data, logged, and governed by internal security policies.
Privacy and AI data use
Clearly AI processes customer-provided data to run reviews, answer questions, automate workflows, and provide configured integrations. Customer-provided data can include uploaded files, tickets, code, pages, Knowledge Base content, review templates, review answers, citations, workflow outputs, and business contact data used for authentication and access control.
Clearly AI does not use customer data to train or fine-tune model providers unless explicitly requested for customer-specific models.
Clearly AI uses Retrieval Augmented Generation so reviews and chat can use customer sources and Knowledge Base context without training a model on that data.
Model data handling and retention depend on your organization's deployment, selected provider, and credential configuration. Clearly AI supports zero-data-retention arrangements for some managed provider configurations. Confirm the terms that apply to your organization before sending regulated data. Clearly AI can also use customer API keys or AWS Bedrock for model calls in supported enterprise deployments. When you use customer-provided credentials, your provider account settings and provider terms also apply. Amazon Bedrock does not use prompts or completions to train AWS models.
For export and deletion requests, see Privacy and data governance.
Governance and compliance
Clearly AI maintains a formal information security program, including policies for access control, incident response, data classification, vulnerability management, audit logging, data retention, secure software development, business continuity, and AI governance.
Clearly AI employees and contractors sign confidentiality agreements. Employees complete security awareness training during onboarding and annually after that.
Clearly AI has completed a SOC 2 audit against the AICPA Security Trust Services Criteria. Prospective customers and customers can request the SOC 2 report under NDA.
Subprocessors and vendors
Clearly AI reviews third-party vendors before use and reassesses critical vendors periodically. Vendor reviews consider security controls, data retention, privacy practices, and security history.
Clearly AI subprocessors are listed at clearly-ai.com/docs/clearly-ai-subprocessors.
Clearly AI also uses its own product to review vendors and subprocessors. Completed reviews can be shared with prospective customers under NDA.