Security by Design, Not Afterthought
Security by Design,
Not Afterthought
Security by Design, Not Afterthought
Our platform is built to protect your data with the same vigilance you bring to your clients' systems. We've done our homework, but we also know that MSPs do this for a living. That's why we aim to be completely transparent about where we are and what’s next when it comes to security.
S
CASA Tier 2 and
SOC II Type 1 Certified
We are CASA Tier 2 certified, a benchmark created by the App Defense Alliance that evaluates the security posture of cloud applications. The Tier 2 audit covers application architecture, data protection, and deployment security. Additionally, we've achieved SOC 2 Type 1 certification, demonstrating our commitment to maintaining rigorous security controls and protecting customer data.


FOUNDED BY


We are technology professionals who believe in getting the fundamentals right from day one. We apply the basics with care, lean on trusted infrastructure, and ask for help when we should.
Zero Trust Enforcement
Clairify enforces Zero Trust at every layer: we never handle your credentials. Instead, login is done through Gmail or Outlook SSO. Every request is authenticated using short-lived tokens. Every action is authorized based on your role, not just your login status. Even our backend has a locked-down identity when accessing data. Finally, all enforcement happens server-side to prevent tampering from compromised apps or devices.
Data Protection
All data is encrypted in transit using TLS and stored at rest with AES-256, so whether it's moving or sitting still, it's unreadable to anyone without the right keys. We never touch your payment details—those stay securely with Stripe and Lemon Squeezy. And when it comes to data retention, each plan has a defined lifespan for data, and you can delete it anytime on demand.
Secure Architecture
Because Clairify is built as a native iOS application, we inherit strong infrastructure security from Apple's platform—reducing risks like DNS vulnerabilities, outdated components, and unmanaged external dependencies.
Resilience & Redundancy
Security isn’t just about keeping the bad guys out—it’s also about bouncing back fast if something goes wrong. We can restore our application from a known-good state quickly, but we have no need to back up your data, it can all be fetched fresh from your email provider!
What's Next?
Security is never finished—we are pursuing CASA Tier 3 certification.

- Full penetration testing. Authorized security labs will conduct thorough testing of our application and infrastructure to identify vulnerabilities.
- Comprehensive infrastructure review. Testing extends beyond the application to include deployment infrastructure and data storage locations.
- Independent Security Verification badge. Upon completion, we'll receive the official badge for Google Workspace Marketplace, demonstrating the highest standard of third-party validated security.
- Annual revalidation. Ongoing commitment to maintaining the most rigorous security standards through yearly reassessment.