Trust Center

Security, privacy and compliance at Clarivexa

Clarivexa runs the compliance programs of regulated organizations across Africa and beyond. We hold ourselves to the same standards our customers use us to meet — with defence-in-depth security, transparent data handling, and continuous independent oversight.

Our security pillars

Encryption everywhere

AES-256 at rest, TLS 1.3 in transit, and encrypted backups. Keys rotated on a documented schedule with hardware-backed storage.

Least-privilege access

Role-based access, SSO/SAML/OIDC, SCIM provisioning, MFA enforcement, and just-in-time production access reviewed quarterly.

Tenant isolation

Every customer's data is logically isolated with row-level security. Cross-tenant queries are structurally impossible.

Continuous monitoring

24/7 log aggregation, anomaly detection, and alerting. All administrative actions are immutably audit-logged.

Resilient infrastructure

Multi-region cloud hosting with automated failover, daily encrypted backups, and documented RTO/RPO targets.

Independent assurance

Regular third-party penetration tests, vulnerability scanning, and secure SDLC with mandatory code review.

Compliance & certifications

Clarivexa aligns to global standards and Africa-specific data protection regimes. We publish current status transparently — including where an audit is still in progress.

ISO/IEC 27001
Aligned — audit in preparation
ISO/IEC 42001 (AI Management)
Aligned
SOC 2 Type II
In progress — expected Q4 2026
GDPR
Compliant
Kenya Data Protection Act 2019
Registered data controller & processor
NIST AI RMF
Adopted as internal framework

How we handle your data

Ownership. You own all data you and your team put into Clarivexa. We act as a data processor on your instructions.

AI training. Your evidence, policies, model metadata, and generated documents are never used to train Clarivexa or third-party AI models.

Data residency. Customer workspaces are hosted in secure cloud regions with documented transfer safeguards where applicable (SCCs, adequacy decisions, Kenya DPA compliant transfer mechanisms).

Retention & deletion. You can export or delete workspace data on demand. Immutable audit logs are retained for at least seven years to preserve inspection integrity.

Subprocessors

We use a small set of vetted providers for hosting, email, and AI inference. Each is reviewed for security posture, data-handling terms, and jurisdictional fit before onboarding.

ProviderPurposeRegion
Amazon Web ServicesPrimary application hosting & storageEU / US
SupabaseManaged database, auth, storageEU
CloudflareEdge network, DDoS protection, WAFGlobal
ResendTransactional email deliveryEU / US
OpenAI / Google / AnthropicAI model inference (no training on your data)US / EU

Incident response

Clarivexa maintains a documented incident response plan aligned with ISO 27035 and NIST SP 800-61. Confirmed incidents affecting customer data are notified without undue delay and within the timelines required by GDPR (Art. 33) and the Kenya Data Protection Act §43.

Documents on request
  • · Security Whitepaper
  • · Data Processing Agreement (DPA)
  • · Penetration Test Summary
  • · Business Continuity & DR Plan
Request documents
Report a vulnerability

We welcome coordinated disclosure from security researchers. Please email findings to our security team; we respond within one business day.

security@clarivexa.io
Read our Privacy Policy and Terms of Service for the contractual detail behind these commitments.