Is this your company?Buyers are checking Clarity AI here. Claim clarity.ai free to control the listing, earn the badge buyers trust, and see who's evaluating you.
Clarity AI, Inc. brings societal impact to markets. Whether customers need a comprehensive, customizable, fully-packaged Sustainability Tech SaaS Platform or just one data point to ensure regulatory compliance, Clarity AI empowers customers to efficiently and confidently assess, analyze and report on anything valuable to them or their clients and everything required by regulation.
We are glad to announce that Clarity AI’s SOC 1 Type II report, covering the 6-month monitoring period from March 1, 2025, to August 31, 2025, is now available for request and download.
New Clarity AI ISO 27001:2022 certificate and SOC 2 type II report are availableAug 2025
We are pleased to announce that Clarity AI has successfully passed its second surveillance audit against the ISO 27001:2022 standard. The Statement of Applicability (SoA) and certificate are now accessible for request and download from our Trust Center. Furthermore, Clarity AI's SOC 2 Type II report, covering the 12-month monitoring period (June 1, 2024, to May 31, 2025) is also available for request and download.
Clarity AI joins the Wiz Zero Critical ClubJun 2025
We’re proud to share that Clarity AI has been officially recognized by Wiz, a leading cloud security platform, as a member of the Zero Critical Club. This distinction means that we currently have no outstanding critical vulnerabilities across our cloud environments – a reflection of our ongoing commitment to security excellence. Achieving this milestone underscores our proactive approach to identifying and remediating risk, and maintaining a secure infrastructure.
Latest Disaster Recovery Test Report availableSep 2024
Our 2024 Disaster Recovery Test Report is now available. This report provides insights into the resilience of our systems and our ongoing commitment to ensuring business continuity.
New Clarity AI ISO 27001 certificate and SOC 2 type II report are availableJul 2024
Clarity AI successfully passed its first surveillance audit against ISO 27001 standard, SoA and certificate are now available to request and download from our Trust Center. Clarity AI's SOC 2 type II report for a 12 months monitoring period (June 1, 2023 to May 31, 2024) is also available to request and download.
This listing is partial
6/11 details · 55%
SOC2C shows the verified essentials. 5 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.
Auditorraises trust
Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
Report dateraises trust
Add your most recent report period so buyers see how current your SOC 2 is.
Renewal date
Add your renewal window so buyers know your coverage is active.
Documents
List the documents you share (SOC 2 report, SOC 3, pen-test summary, DPA) and whether each is public or on request.
Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.
Frequently asked
Is Clarity AI SOC 2 compliant?
Clarity AI is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Clarity AI ISO 27001 certified?
According to Clarity AI's public trust center, Clarity AI is ISO 27001 certified. On SOC2C this listing is Listed.
Is Clarity AI CSA STAR certified?
According to Clarity AI's public trust center, Clarity AI is CSA STAR certified. On SOC2C this listing is Listed.
Is Clarity AI SOC 2 Type I or Type II?
Clarity AI is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Clarity AI's SOC 2 for a vendor risk assessment?
Yes. Clarity AI's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Clarity AI penetration tested?
Clarity AI hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.
Is Clarity AI secure?
Security isn't a single yes/no, but Clarity AI is SOC 2 Type II compliant and holds ISO 27001, SOC 2 Type II, CSA STAR. SOC2C verifies its compliance posture and shows how strongly each fact is proven.
Does Clarity AI have a bug bounty or vulnerability disclosure program?
Clarity AI hasn't listed a bug bounty or vulnerability disclosure program on SOC2C. Many companies accept security reports at security@clarity.ai or via a /security page (Clarity AI lists a security contact).
Who are Clarity AI's subprocessors?
Clarity AI lists 6 subprocessors on its trust center, including Amazon Web Services, Microsoft Azure, OpenAI, Snowflake, MongoDB Atlas. Buyers use this for fourth-party risk review.
Where does Clarity AI host or store data?
Clarity AI hosts on AWS, Azure, and handles Employee personally identifiable information, Customer user business credentials for access to Clarity AI Services. Data residency details are on its trust center.
Where is Clarity AI's trust center or security page?
Clarity AI's trust center is at https://trust.clarity.ai. Its verified SOC 2 status, frameworks, and documents are summarized on its SOC2C profile.
How does Clarity AI manage the environmental footprint of its AI?
We are committed to building responsible and sustainable AI, aligned with our core mission of bringing societal impact to markets. Our approach to minimizing the environmental footprint of AI includes: - Use of resource-efficient models: We favor smaller, specialized models wherever possible to minimize energy usage without compromising accuracy. - Green cloud infrastructure: Our systems are hosted on cloud providers committed to net-zero goals, with compute operations run in carbon-efficient regions. - Lifecycle assessments and impact tracking: We track compute consumption associated with AI model training and inference and aim to incorporate AI lifecycle metrics into our broader ESG reporting practices.
What measures does Clarity AI take to ensure its AI models are fair, transparent, and explainable?
We follow a Responsible AI framework grounded in transparency, fairness, and regulatory readiness: - Auditability and documentation: Every model we deploy undergoes rigorous documentation through model cards and accuracy and risk assessments. - Bias and fairness testing: We regularly assess our models for disparate impact across demographic and geographic segments, particularly in sustainability and regulatory contexts. - Explainability: Outputs include interpretable rationale, as we provide human-readable justifications, traceability to source data, and explainable methodology and scores. - Governance and oversight: Clarity AI maintains an internal and cross-functional AI and Data Governance Committee to review model performance and alignment with our Responsible AI charter.
Can clients audit or review the outputs generated by Clarity AI’s models?
Yes, our platform offers full traceability and auditability of AI-generated outputs: - Data lineage: Clients can trace results back to the underlying data points and classification logic, supporting full auditability. - Private and segregated data handling: Client-specific data (e.g., investment portfolios) is processed in logically segregated environments and is never co-mingled or reused across clients. - Responsible data use: No client data used for model training (see details in the next question).
Does Clarity AI use client data to train its AI models?
No, we do not use client data to train any of our AI models. We are fully committed to safeguarding our clients’ data privacy. Our AI systems, including generative models, are trained exclusively on data sources that exclude customer data. We also ensure that our technology partners and vendors follow the same principles — client data is never used for model training or fine-tuning under any circumstances.
How does Clarity AI protect sensitive client data?
We implement rigorous measures to ensure the confidentiality, integrity, and security of all client data, including: - Robust security measures: All systems are configured following industry best practices, including strong user authentication, secure APIs, and strict access controls to protect AI systems and associated data. - Zero data retention policy: Our AI systems do not retain any sensitive client data beyond what is necessary for real-time or immediate processing. This principle is core to our commitment to data minimization. - Third-party risk management: We conduct comprehensive third-party risk assessments to ensure all vendors and service providers meet our high security and privacy standards, including those who support AI systems or infrastructure. - Data protection and privacy compliance: All personal and sensitive data is handled in accordance with applicable data protection regulations (e.g., GDPR, CCPA). Data is encrypted both in transit and at rest using robust cryptographic standards. - Responsible data use: We do not use client data to train or fine-tune any AI models. As part of our quality assurance efforts, we may review anonymized or client-authorized interactions with our AI Assistant in a controlled and secure environment. This enables performance monitoring and continuous improvement without compromising privacy.
Do you comply with EU GDPR?
Clarity AI takes appropriate measures to comply with applicable data protection legislation. Relevant policies and procedures are in place to address topics such as data protection, privacy, impact analysis, data subject requests, and processing activities. For more information please see our Privacy Policy Please note Clarity AI acts as the data controller for the services it provides. Our solution is not aimed at the processing of personal data and we therefore minimize its collection & processing. The data made available in our products consists mainly in scores and metrics, which are not personal data.
What type of data does Clarity AI collect?
Clarity AI collects and processes only the minimum data necessary to deliver its services securely and effectively. These data categories include: - User authentication data: We require a unique email address for each authorized user to provide secure access to the Clarity AI platform. Clients may choose to use generic, non-personal email aliases (e.g., analysis@example.com) or personal business emails. If a personal email is used, it may be considered personal data under applicable data protection laws (e.g., GDPR). - Platform usage data: We collect limited metadata related to platform usage (e.g., login timestamps, feature access) to improve platform reliability and security, and to support audit and compliance needs. - Client-provided business data: Clients may upload business-relevant data such as portfolio holdings, ESG metrics, or classification preferences. This data is used solely to provide the services requested and is processed in secure, logically segregated environments. - No special category or sensitive data: Clarity AI does not collect or require sensitive personal data (e.g., biometric, health) for any purpose. All data processing activities are conducted in compliance with applicable privacy laws and our Privacy Policy.
Do you have an established bug bounty program?
Clarity AI VULNERABILITY DISCLOSURE POLICY This vulnerability disclosure policy applies to any vulnerabilities you are considering reporting to us. We recommend reading this vulnerability disclosure policy fully before you report a vulnerability and always acting in compliance with it. We value those who take the time and effort to report security vulnerabilities according to this policy. However, we do not offer monetary rewards for vulnerability disclosures. REPORTING If you believe you have found a security vulnerability, please submit your report to [security@clarity.ai](mailto:security@clarity.ai) . In your report, please include details of: - The website, IP or page where the vulnerability can be observed. - A brief description of the type of vulnerability, for example; "XSS vulnerability". - Steps to reproduce. These should be benign, non-destructive, and proof of concept. This helps to ensure that the report can be triaged quickly and accurately. It also reduces the likelihood of duplicate reports, or malicious exploitation of some vulnerabilities, such as sub-domain takeovers. WHAT TO EXPECT After you have submitted your report, it will be triaged and we aim to respond all valid/accepted reports promptly, usually within 5 working days. Priority for remediation is assessed by looking at the impact, severity and exploit complexity. Vulnerability reports might take some time to triage or address. You are welcome to enquire about the status by contacting [security@clarity.ai](mailto:security@clarity.ai) , but should only do so once every 14 days. This allows our teams to focus on the remediation. If your report is accepted, we will notify you when the vulnerability is remediated, and you may be invited to confirm that the solution covers the vulnerability adequately. Once your vulnerability has been resolved, we welcome requests to disclose your report. We'd like to unify guidance to affected users, so please do continue to coordinate public release with us…