Security by Design, Not Afterthought
Security by Design,
Not Afterthought
Security by Design, Not Afterthought
Our platform is built to protect your data with the same vigilance you bring to your clients' systems. We've done our homework, but we also know that MSPs do this for a living. That's why we aim to be completely transparent about where we are and what’s next when it comes to security.
S
CASA Tier 2 Certified
We are CASA Tier 2 certified, a benchmark created by the App Defense Alliance that evaluates the security posture of cloud applications. The Tier 2 audit covers application architecture, data protection, and deployment security.

FOUNDED BY


We are technology professionals who believe in getting the fundamentals right from day one. We apply the basics with care, lean on trusted infrastructure, and ask for help when we should.
Zero Trust Enforcement
Clairify enforces Zero Trust at every layer: we never handle your credentials. Instead, login is done through Gmail or Outlook SSO. Every request is authenticated using short-lived tokens. Every action is authorized based on your role, not just your login status. Even our backend has a locked-down identity when accessing data. Finally, all enforcement happens server-side to prevent tampering from compromised apps or devices.
Data Protection
All data is encrypted in transit using TLS and stored at rest with AES-256, so whether it's moving or sitting still, it's unreadable to anyone without the right keys. We never touch your payment details—those stay securely with Stripe and Lemon Squeezy. And when it comes to data retention, each plan has a defined lifespan for data, and you can delete it anytime on demand.
Secure Architecture
Because Clairify is built as a native iOS application, we inherit strong infrastructure security from Apple's platform—reducing risks like DNS vulnerabilities, outdated components, and unmanaged external dependencies.
Resilience & Redundancy
Security isn’t just about keeping the bad guys out—it’s also about bouncing back fast if something goes wrong. We can restore our application from a known-good state quickly, but we have no need to back up your data, it can all be fetched fresh from your email provider!
What's Next?
Security is never finished—we are pursuing CASA Tier 3 and SOC II Type 1 certifications.

- Continuous monitoring. Ongoing scans and system checks to identify vulnerabilities and misconfigurations.
- 3rd-party validations. More frequent independent audits by authorized security labs.
- Incident response plan. Fully documented, tested, and rapidly executable incident response plan.
- Proactive threat detection. Watch for unusual behaviour or known attack patterns and surface them in real-time.
Be the first to try Clairify
Our Beta is almost ready! Give us your unvarnished opinion so we can make something the MSP community will absolutely love!
By submitting your email address, you agree to receive communications from Clairify. For more information, please read our privacy policy. You can always withdraw your consent.