Know Your Vendor

Run your diligence on us.

Clarier grades every AI vendor against a standard set of trust criteria. This page answers the same criteria for Clarier, drawn directly from our corporate policies, with the documents below for your files.

Security questionnaire? Send it to security@clarier.ai.

Clarier Technologies, LLCSELF-REPORT · SOURCED TO RATIFIED POLICY
A
Trains on customer dataNo. Customer Data is not used to train, fine-tune, or otherwise modify the parameters of any model, and third-party AI providers are contractually prohibited from training on data transmitted to them.AI Governance Policy §7; Data Privacy Policy §8.3
Raw integration dataNot persisted. Integration data is processed in real time and discarded; only derived records are retained.Data Handling Policy §5.3, §10
File and message contentFile contents, message bodies, document text, and similar substantive content are not extracted or stored.Data Handling Policy §6
AI call retentionRaw inputs and outputs of AI model calls are not retained; metadata (model identifier, timestamp, operational context) is retained.AI Governance Policy §13
EncryptionTLS 1.2+ in transit; AES-256 at rest; credentials carry additional application-layer encryption, decrypted only server-side.Cryptography Policy §5–8
Tenant isolationRow-level security at the database layer; cross-tenant access architecturally prevented.Data Handling Policy §8, §12
Audit logImmutable, tamper-resistant, retained permanently.Data Handling Policy §9
SubprocessorsAssessed before engagement and periodically thereafter; current list available on request.Data Handling Policy §15
SOC 2Type I and Type II in progress · Johanson LLP · monitored continuously in Vanta · report available under NDA on completion.
Breach historyNone.

The same criteria we grade every vendor on. Sources cited to the policy section that governs each answer.

How Clarier Uses AI

The question we taught the market to ask, answered for ourselves.

Models
Established enterprise providers, with model versions pinned in configuration. No self-hosted open-source models.
Where it runs
Dedicated infrastructure where supported, so prompts and outputs are not accessible to the model provider or any third party.AI Governance Policy §8
Scoring
Quantitative scores that drive decisions are calculated deterministically by fixed formula. The model does not produce them.AI Governance Policy §10
Human oversight
AI-generated changes to persisted records are held for explicit approval, and external communications are never dispatched autonomously.AI Governance Policy §9
Disclosure
AI-generated content is identified to users, and provenance metadata is available for review.AI Governance Policy §12
Data Lifecycle

Retention, deletion, and the one deliberate exception.

Retention
For the duration of the relationship, then available for export for thirty days after termination, after which it is deleted per the customer agreement.Privacy Policy §10
Deletion requests
Verified requests complete within thirty days under a documented three-phase procedure. The request record itself is retained as evidence.Data Handling Policy §16
The exception
Audit logs are immutable and permanent, to support compliance and forensic review.
DPA
Available from legal@clarier.ai.
Still Diligencing

Ask us the hard questions.

A short call with the people accountable for these answers.