Know Your Vendor

Run your diligence on us.

Clarier grades every AI vendor against a standard set of trust criteria. This page answers the same criteria for Clarier, drawn directly from our corporate policies, with the documents below for your files.

Security questionnaire? Send it to security@clarier.ai.

Clarier Technologies, LLCSELF-REPORT · SOURCED TO RATIFIED POLICY
A
Trains on customer dataNo. Customer Data is not used to train, fine-tune, or otherwise modify the parameters of any model, and third-party AI providers are contractually prohibited from training on data transmitted to them.AI Governance Policy §7; Data Privacy Policy §8.3
Raw integration dataNot persisted. Integration data is processed in real time and discarded; only derived records are retained.Data Handling Policy §5.3, §10
File and message contentFile contents, message bodies, document text, and similar substantive content are not extracted or stored.Data Handling Policy §6
AI call retentionRaw inputs and outputs of AI model calls are not retained; metadata (model identifier, timestamp, operational context) is retained.AI Governance Policy §13
EncryptionTLS 1.2+ in transit; AES-256 at rest; credentials carry additional application-layer encryption, decrypted only server-side.Cryptography Policy §5–8
Tenant isolationRow-level security at the database layer; cross-tenant access architecturally prevented.Data Handling Policy §8, §12
Audit logImmutable, tamper-resistant, retained permanently.Data Handling Policy §9
SubprocessorsAssessed before engagement and periodically thereafter; current list available on request.Data Handling Policy §15
SOC 2Type I and Type II in progress · Johanson LLP · monitored continuously in Vanta · report available under NDA on completion.
Breach historyNone.

The same criteria we grade every vendor on. Sources cited to the policy section that governs each answer.

How Clarier Uses AI

The question we taught the market to ask, answered for ourselves.

Clarier’s AI runs through established enterprise providers with model versions pinned in configuration; no open-source models are self-hosted. Where supported, processing runs in dedicated infrastructure so prompts and outputs are not accessible to the model provider or any third party (§8). Quantitative scores that drive decisions are calculated deterministically, not generated by AI (§10). Consequential actions carry human oversight: AI-generated changes to persisted records are held for explicit approval, and external communications are never dispatched autonomously (§9). AI-generated content is identified to users, and provenance metadata is available for review (§12).

All references above are to the AI Governance Policy.

Data Lifecycle

Retention, deletion, and the one deliberate exception.

Customer Data is retained for the duration of the relationship and is available for export for thirty days after termination, after which it is deleted per the customer agreement (Privacy Policy §10). Verified deletion requests complete within thirty days under a documented three-phase procedure, with the request record retained as evidence (Data Handling Policy §16). Audit logs are the deliberate exception: immutable and permanent, to support compliance and forensic review. A Data Processing Agreement is available from legal@clarier.ai.

Still Diligencing

Ask us the hard questions.

A short call with the people accountable for these answers.