Legal
Privacy Policy
How ClearSOC collects, uses, and protects information — for our website, our application, and the security data we process on your behalf.
Effective July 31, 2026
Overview
ClearSOC provides a multi-tenant, AI-assisted security operations platform. This policy explains what information we collect, how we use it, and the choices you have. It applies to our website and to the ClearSOC application. For customers, our Data Processing Agreement governs how we process security data on your behalf.
Information we collect
- Account & contact information — name, work email, company, and details you provide when you sign up, request a demo, or apply to the partner program.
- Security telemetry — when you connect an integration (Microsoft 365, Google Workspace, AWS) over OAuth, we ingest the security events and asset inventory needed to detect and investigate threats for your tenant.
- Usage & technical data — log data, IP address, device/browser information, and product usage needed to operate, secure, and improve the service.
How we use information
We use information to provide and secure the service — detecting, triaging, and helping you respond to security incidents — to support you, to meet legal and billing obligations, and to improve the product. We do not sell your personal information or your security telemetry.
AI-assisted analysis
ClearSOC uses large-language-model analysis (via Anthropic) to explain and prioritize incidents. Relevant incident context may be sent to that provider solely to generate the analysis; it is not used to train third-party models. Tenants can disable AI analysis entirely, or enable pseudonymization so identifiers are masked before any content leaves our systems. High-risk response actions always require human approval.
Sharing & subprocessors
We share information only with service providers that help us run the platform — cloud infrastructure, our AI analysis provider, and our transactional email provider — each under contractual confidentiality and data-protection terms. We may disclose information if required by law. A current list of subprocessors is available to customers on request.
Security
Every tenant's data is isolated, with separation enforced at the database layer. Data is encrypted in transit and at rest, integrations are OAuth-only (we never ask for passwords), authentication uses httpOnly cookies rather than browser-accessible tokens, and access is limited to the personnel who need it. See our security page for detail.
Data retention
We retain account information for as long as your account is active and as needed to meet legal obligations. Security telemetry is retained per your plan and configuration; on termination we delete or return tenant data on request, subject to legal retention requirements.
Your rights
Depending on where you live, you may have rights to access, correct, delete, or port your personal information, and to object to or restrict certain processing. To exercise these rights, contact us at privacy@clearsocapp.com. Where we process security data on a customer's behalf, we will refer individual requests to that customer.
International transfers
We may process information in countries other than your own. Where required, we use appropriate safeguards (such as Standard Contractual Clauses) for such transfers.
Data Processing Agreement (DPA)
For customers who process personal data through ClearSOC, we make a Data Processing Agreement available that sets out our roles, security commitments, and subprocessor terms. Request a copy at privacy@clearsocapp.com.
Changes
We may update this policy from time to time. Material changes will be reflected here with a new effective date.
Questions about privacy or data protection? Contact privacy@clearsocapp.com.