
Loading CompliClear

Loading CompliClear
Control summary updated 12 July 2026. This page describes implemented safeguards and open assurance boundaries without claiming a certification.
Clerk provides authentication and session controls. CompliClear requires the verified primary email for email-based account and invitation binding, blocks silent identity rebinding, applies company-scoped database queries, and enforces Viewer, Editor, Admin, Support, or Super Admin checks at protected actions.
Production traffic is expected to use HTTPS with HSTS. New generated PDFs and uploaded evidence are stored with private provider references; downloads pass through authenticated workspace authorization. Evidence deletion removes the object before deleting its database record. Database and object encryption at rest are supplied by the configured infrastructure account.
CompliClear uses hosted checkout and does not intentionally receive full card numbers or card security codes. Dodo webhook events are verified against the exact raw request body and Standard Webhooks signature/timestamp headers, correlated with a stored checkout session or subscription, and processed idempotently. Cancellation, hold, refund, and dispute states can revoke entitlements.
Use strong authentication, protect devices, review team access, remove stale invitations, minimize uploads, and verify every output. Do not upload secrets, payment cards, raw health records, biometric templates, child records, government IDs, or other prohibited sensitive data without a separately signed agreement and appropriate controls.
Suspected incidents are triaged for containment, affected systems/data, controller/processor role, customer impact, evidence, root cause, remediation, and applicable reporting windows. Processor notices are provided to affected customers without undue delay when required. Applicable controller deadlines may include GDPR's risk-based 72-hour regulator assessment and India's current CERT-In directions for listed incidents.
CompliClear is not currently SOC 2 certified, ISO 27001 certified, PCI validated by a QSA, or independently penetration-tested under a published assurance report. Hosted checkout can reduce card-data scope but does not eliminate merchant/service-provider obligations. Customers needing formal assurance evidence must contact founder@compliclear.com before regulated production use.
Send a clear description, affected URL, safe reproduction steps, impact, and contact details to security@compliclear.com if available, otherwise support@compliclear.com. Do not access other customers' data, disrupt service, use social engineering, or publish exploitable details before coordinated remediation. The machine-readable policy is available at /.well-known/security.txt.