Security
How your data is held, and how we keep it that way
You are handing over your books, so you should know exactly what happens to them. Every claim on these pages names the thing that enforces it: a database permission, a transport guard, an identity check. Where a claim touches regulation we say the design is meant to support the obligation, not that we are certified against it. We also say plainly what we do not have yet.
Two things to keep separate while you read. The public demo at demo.claritybriefing.com is open on purpose so anyone can try it, and it holds only the fictional Spark Digital company. A real client deployment is private, behind a login, and holds only your data. The pages below note which is which where it matters.
-
Your data
Read-only access to your accounting system, client data hosted in the EU, your database isolated from every other client, and the right to revoke or leave with your data.
-
The pipeline in detail
How a figure gets from your accounting system to the dashboard. The numbers move one way, no model sits in the calculation, and every figure traces back to its source.
-
The AI analyst
What the analyst can see, why it cannot change anything, how revenue is reconciled against your accounting system, and the limits we are honest about.
-
Access and authentication
How client dashboards and AI connections are protected: a managed identity provider, passwordless email codes, an allowlist that denies by default, and a startup self-test.
-
Regulatory posture
How the design is meant to support POPIA and FSCA obligations, the sub-processors we use, and a plain statement of what we do not yet have.
-
Security FAQ
The blunt questions a buyer asks before handing over their books, each answered with the mechanism that backs it and a link to the page that proves it.