Trust Center

Your data, protected at every layer

Organizations in 190+ countries trust Claform with sensitive feedback data. This is where we show our work: the controls, practices, and documents behind that trust.

99.9%
Uptime SLA
AES-256-GCM
Encryption at rest
TLS 1.3
Encryption in transit
24/7
Security monitoring

Compliance

Built for regulated industries

Claform is designed to align with the data protection regulations our customers answer to — with the documentation to prove it.

GDPR

Full compliance

Data subject rights, consent management, 72-hour breach notification, and a comprehensive Data Processing Agreement (DPA).

SOC 2

Aligned to Type II controls

Built around the SOC 2 Type II trust principles of security, availability, and confidentiality. Current security documentation available under NDA.

HIPAA

BAA available

Business Associate Agreement for healthcare organizations, with compliant data handling, access controls, and audit logging for PHI.

ISO 27001

Aligned

Information security management practices aligned with ISO 27001 standards across people, processes, and technology.

TCPA

Built-in

Consent tracking and opt-out management for SMS and voice campaigns, enforced at the platform level.

CASL

Built-in

Canadian Anti-Spam Legislation compliance for email and SMS distribution, including consent records and unsubscribe handling.

Responsible Disclosure

Found a vulnerability? We work with security researchers under a responsible disclosure program with safe harbor protection. Report issues directly to our security team and we will respond promptly.

[email protected]

Have Security Questions?

Schedule a security review with our team. We are happy to walk through our architecture, complete your questionnaires, and share documentation under NDA.