At Clarus, protecting our clients' data and systems is foundational to everything we do. We hold ourselves to high standards of security, privacy, and operational integrity so our clients can focus on their business with confidence.
Security isn't a checklist — it's built into how we operate, deliver services, and manage our own infrastructure.
All client data is encrypted in transit and at rest using industry-standard protocols. We enforce TLS 1.2+ for all communications and AES-256 for stored data.
We enforce role-based access, multi-factor authentication, and the principle of least privilege across all systems and client environments.
Third-party vendors are evaluated for security posture before onboarding and reviewed on an ongoing basis to ensure continued compliance with our standards.
All team members complete security awareness training and are trained on data handling procedures, phishing identification, and incident escalation.
We maintain a documented incident response plan with defined roles, communication procedures, and post-incident review processes.
Our environments are monitored around the clock for threats, anomalies, and unauthorized access using centralized logging and alerting.
We align our practices with recognized security frameworks and are actively pursuing formal certification.
We are actively pursuing SOC 2 Type II certification to provide independent assurance of our security, availability, and confidentiality controls.
Our security program is structured around the NIST CSF, covering identification, protection, detection, response, and recovery.
We implement CIS Controls as a practical baseline for hardening systems, managing vulnerabilities, and reducing attack surface.
We treat every client's data with the same rigor we apply to our own.
We collect only the data necessary to deliver our services. Client data is stored in secure, access-controlled environments with encryption at rest and in transit.
Data is retained only as long as required by the applicable service agreement or legal obligation. When no longer needed, data is securely deleted or destroyed in accordance with our retention policies.
We do not sell client data. Information is shared with third parties only when necessary to deliver services (e.g., cloud hosting providers), and all vendors are held to contractual security obligations. For details, see our Privacy Policy.
Have questions about our security practices? Need to submit a vendor security questionnaire or request additional documentation? We're happy to help.
info@clarusinc.comReturn to Home