Trust Center
v1.0 · Effective 2026-07-09 · Updated 2026-07-09Clarika turns documents into structured data for operations, finance, and compliance teams. Because that work often involves sensitive material, this page is a single, plain-language summary of how we protect your data, who we share it with, and what rights you have. It is written to answer the questions that appear on most vendor security questionnaires without a call.
We keep this page honest. Where a control is fully in place we say so; where it is partial or still on our roadmap, we say that too, with a target. If you need something not covered here — a signed questionnaire (SIG / CAIQ), a penetration test summary, or a Data Processing Agreement — email security@clarika.co.ke.
Status legend: 🟢 In place · 🟡 Partial · 🔵 Planned
Data protection
| Control | Status | Detail |
|---|---|---|
| Encryption in transit | 🟢 In place | All traffic to Clarika is served over TLS. HTTP Strict Transport Security (HSTS) is enforced at the edge, so browsers only ever connect over HTTPS. |
| Encryption at rest | 🟡 Partial | Application-level secrets and third-party credentials are encrypted at rest (Fernet / AES). Full disk- and object-storage-level at-rest encryption for the primary database and document store is being formalized and documented — targeted for 2026-Q4. |
| Secret management | 🟢 In place | Provider keys and integration tokens are encrypted before storage and are never returned to the browser. |
| Network isolation | 🟢 In place | Application services run behind a single reverse proxy; internal services (database, object storage, task queue) are not exposed to the public internet. |
We do not train AI models on your documents, and our AI sub-processor (Anthropic) does not use content sent through the API to train its models.
Data residency & hosting
Clarika's application and primary data store are operated by our team on managed infrastructure. Some processing is performed by sub-processors located in the United States and the European Union (see the table below). Where a sub-processor is outside Kenya, transfers are made under the safeguards described in our Data Processing Agreement.
Sub-processors
We use a small set of vendors to deliver the product. We notify customers at least 30 days before adding or replacing a sub-processor that processes personal data, so you have time to object.
| Sub-processor | Purpose | Region |
|---|---|---|
| Supabase | Authentication & managed Postgres | Managed |
| MinIO | Document & object storage | Self-hosted |
| Reducto | Document parsing & extraction | United States |
| Anthropic | AI model inference | United States |
| Resend | Transactional email | United States |
| Twilio | Notifications | United States |
| Sentry | Error monitoring | European Union |
| PostHog | Product analytics | European Union |
The authoritative, versioned list — including what each vendor processes — is maintained at Sub-processors.
Your data rights
You can exercise your data rights yourself, from inside the product, under
Settings → Privacy (/settings/privacy):
- Export. Request a machine-readable export of your account data. We generate a download link, valid for 7 days.
- Deletion. Request deletion of your account and associated data. Deletion runs after a 30-day grace period, during which you can cancel.
These rights are provided under the Kenya Data Protection Act, 2019, which also gives you the right to access, correct, and object to processing. For requests that can't be completed self-service, email privacy@clarika.co.ke.
In progress: an API-driven "restrict processing" flow is on our roadmap. Until it ships, restriction requests are handled manually — email us and we will action them.
Incident & breach response
We maintain a documented incident-response process with defined notification timelines:
- Internal declaration: a suspected breach is declared and triaged within 24 hours of detection.
- Customer notification: affected customers are notified within 48 hours of confirming a breach that affects their data.
- Regulator notification: the Office of the Data Protection Commissioner (ODPC) is notified within 72 hours where the Kenya DPA requires it.
- Data subjects: notified without undue delay where a breach is likely to result in a high risk to their rights.
Access control & authentication
- Sign-in is handled by a managed authentication provider (Supabase) with support for email/password and OAuth.
- Access to production systems is limited to a small number of operators.
- Provider credentials and API tokens are encrypted and scoped per workspace.
Product analytics & privacy
- Product analytics (PostHog) is consent-gated — we do not load analytics until you accept, and it is hosted in the European Union.
- We do not use session recording or screen capture.
- See our Privacy Policy for the full description of what we collect and why.
Compliance & certifications
We are an early-stage company building toward formal certification. We will not claim a certification we do not hold. Current status:
| Framework | Status | Target |
|---|---|---|
| Kenya Data Protection Act, 2019 | 🟢 Operating under | — |
| SOC 2 (Type II) | 🔵 Pre-audit — control inventory underway; auditor to be selected | TBD |
| ISO/IEC 27001 | 🔵 Aspirational | 2027-Q2 |
| Data Protection Impact Assessment (DPIA) | 🟡 Template + triggers published; sign-off pending | 2026-Q3 |
| ODPC data-handler registration | 🔵 In progress | 2026-Q3 |
Under the Kenya DPA, Clarika acts as a data processor for the documents and content you upload, and as a data controller for the account information we need to run the service.
Reporting a vulnerability
We welcome coordinated disclosure from security researchers.
- Email: security@clarika.co.ke
- Acknowledgement: within 3 business days.
- Coordinated disclosure window: 90 days.
To send us something sensitive, encrypt it to our PGP key:
- Key ID:
E09D9E03 - Fingerprint:
5A5E 6748 7C2E F440 53D6 7AD4 C997 EE8B E09D 9E03 - Type: Ed25519 · Expires: 2029-06-23
Please do not access or modify data that isn't yours, and give us reasonable time to remediate before any public disclosure.
Legal documents
Contact
| Topic | Address |
|---|---|
| Security & vulnerability reports | security@clarika.co.ke |
| Privacy & data-rights requests | privacy@clarika.co.ke |
| Everything else | hello@clarika.co.ke |
This page is a summary of our current posture and is updated as our program matures. It does not itself form part of any contract; where it differs from a signed agreement, the agreement governs.