Skip to content

Security / Compliance

Regulatory posture

Clarity is built to support the obligations a South African business carries when it handles financial data. We say designed to support, not compliant: the obligations sit with you as the responsible party, and the architecture is meant to make meeting them straightforward. This page also states plainly what we do not yet have.

POPIA: operator and responsible party

Under POPIA you are the responsible party for your data and Clarity acts as your operator, processing it on your instruction and for your purposes. Client data is hosted in the EU, which carries recognised data-protection standards relevant to cross-border processing.

Data-subject rights, mapped to mechanisms

The rights a data subject can exercise map to things the system can actually do:

  • Access. Every figure traces back to its source record and can be produced.
  • Correction. Corrections are made in your accounting system, the source of truth, and flow through on the next sync.
  • Deletion. Your database can be deleted in full when the engagement ends.
  • Objection. You can revoke Clarity's access to your accounting system at any time, which stops further processing.
  • Portability. You can take a full export of your data in a standard format.

FSCA: designed to support oversight

For financial-services clients, the design leans toward what a regulator wants to see. The figures are inspectable SQL rather than a black box, access and activity are logged, and the AI analyst recommends rather than acts. A person stays in the decision, and the working is open to audit.

A server-side tokenisation layer is available for regulated clients.

For clients who need it, queries can be keyed on tokens rather than real names, bulk export of names is blocked, and name resolution is confined to a user's own authorised queries and done on the server. This is an option for regulated clients, not a platform default, and we do not claim it means the AI never sees a real name.

Encryption

Data is encrypted in transit using TLS. At rest, it relies on the hosting platform's disk encryption. We do not claim an additional layer of encryption at rest beyond that.

Sub-processors

A small set of providers sit behind Clarity. We name them by role:

  • Render Hosting and database
  • Anthropic AI analyst
  • Auth0 Authentication
  • Resend Delivery of one-time email codes

What we do not have yet

There is no SOC 2 report, no ISO 27001 certification, and no third-party penetration test at present. We would rather say so than imply otherwise. The basis for trust is what the rest of these pages describe: tested gates that fail closed, and a pipeline you can inspect end to end.