Security

Enterprise-grade security

We take the security of your risk data seriously. CleRisk is built with security at its core.

Security & compliance

Industry-leading security measures to protect your data

Encryption

All data is encrypted at rest (AES-256) and in transit (TLS 1.3)

Secure cloud hosting

Your data is hosted in secure, access-controlled data centres

Access controls

Role-based access control with audit logging

SOC 2 (in progress)

Working towards certification; controls aligned to SOC 2.

GDPR compliant

Full compliance with EU data protection regulations

ISO 27001 (in progress)

Working towards certification; ISMS controls in place.

Our security practices

Independent penetration testing — planned ahead of general availability

Automated dependency and vulnerability scanning

Least-privilege access controls and security-aware engineering

A documented incident-response plan

Periodic security reviews

Encrypted database backups and disaster-recovery procedures

Data protection

Your risk data is sensitive, and we treat it with the utmost care. All data is encrypted using AES-256 encryption at rest and TLS 1.3 in transit. We maintain strict access controls and audit logging to ensure only authorised personnel can access your information.

We are fully compliant with GDPR and other applicable data protection regulations. Your data is hosted in secure, access-controlled data centres, and we never share it with third parties without your explicit consent.

We carry out internal security reviews and automated vulnerability scanning, with independent penetration testing planned ahead of general availability. Personal identifiers are minimised before any AI processing, and access to systems is least-privilege and logged.

Report a security vulnerability

If you believe you've found a security vulnerability in CleRisk, please report it to us responsibly. We appreciate your help in keeping our platform secure.

security@clerisk.com