Security and data handling
What we store, where it goes, and what we never do. Written for the person running vendor diligence.
The honest posture
ClearForge is a founder-led firm. We do not hold a SOC 2 certification today and we will not imply otherwise. What we do hold is a short, real list of practices, stated below so your security review can start from facts.
Where your data lives
Form submissions and diagnostic results are stored in Supabase with row-level security. The public site key can only read what the site needs; writes happen server-side with scoped credentials. Files you attach (RFPs, briefs) go to a private storage bucket with no public URLs, renamed to random identifiers, size-capped, and restricted to document types.
AI processing
The diagnostic tools process the text you submit and publicly available pages from the address you provide. We use enterprise API terms with our model providers that exclude your data from model training. We never fetch anything behind a login.
Subprocessors
The services that run this site, each bound by its own terms:
- Vercel: hosting and delivery
- Supabase: storage of submissions and attached files
- Anthropic: AI processing, enterprise API terms, no training on your data
- Resend: transactional email
- Cal.com: scheduling, under its own privacy policy
- Google Analytics: website analytics
Client engagements
Engagement work runs in your systems wherever possible, under your access controls. Credentials we hold are scoped to the minimum, stored in a password manager, and revoked at engagement end. Client data, processes, and engagement details are never disclosed without written consent; published case studies are anonymized and client-approved.
A data processing agreement is available on request, and we will complete your vendor security questionnaire as part of any engagement.
Questions, or a questionnaire to complete? Email james@clearforge.ai or read the privacy policy.