Security Overview

Version 0.9-draft · Effective 2026-08-18 · Applies to: All customers

The technical and administrative controls Clarity Harbor operates. Descriptive, not a certification claim.

Draft. Draft pending qualified legal review. This document describes how Clarity Harbor intends to operate and is published for transparency. It is not an executed agreement and does not yet form binding terms. Final language will be reviewed and approved by legal counsel before activation.

Controls in place

Authentication and role-based authorization on internal systems, token-scoped access to customer deliverables, private file storage with per-object access control, encrypted transport, managed secrets, audit logging of administrative actions, least-privilege service access, and managed backups.

What is not claimed

Clarity Harbor does not currently hold SOC 2, ISO 27001 or any other third-party security certification, and does not claim regulatory compliance certification. Any such claim will appear here only when it is accurate and evidenced.

Reporting a concern

Suspected vulnerabilities or data concerns can be reported to hello@joinclarityharbor.com. Reports are acknowledged and investigated.

Questions: hello@joinclarityharbor.com