Trust Center
Your data, protected at every layer
Organizations in 190+ countries trust Claform with sensitive feedback data. This is where we show our work: the controls, practices, and documents behind that trust.
Compliance
Built for regulated industries
Claform is designed to align with the data protection regulations our customers answer to — with the documentation to prove it.
GDPR
Full complianceData subject rights, consent management, 72-hour breach notification, and a comprehensive Data Processing Agreement (DPA).
SOC 2
Aligned to Type II controlsBuilt around the SOC 2 Type II trust principles of security, availability, and confidentiality. Current security documentation available under NDA.
HIPAA
BAA availableBusiness Associate Agreement for healthcare organizations, with compliant data handling, access controls, and audit logging for PHI.
ISO 27001
AlignedInformation security management practices aligned with ISO 27001 standards across people, processes, and technology.
TCPA
Built-inConsent tracking and opt-out management for SMS and voice campaigns, enforced at the platform level.
CASL
Built-inCanadian Anti-Spam Legislation compliance for email and SMS distribution, including consent records and unsubscribe handling.
Defense in depth
Security at every layer
Six overlapping control domains protect your data — no single point of failure. Each links to the full technical detail in our whitepaper.
Infrastructure
AWS multi-AZ hosting, VPC network isolation, DDoS protection with WAF, and automated backups with point-in-time recovery.
Read in the whitepaperApplication Security
Layered input validation, OWASP Top 10 coverage, continuous dependency scanning, and third-party penetration testing.
Read in the whitepaperData Protection
AES-256-GCM encryption at rest, TLS 1.3 in transit, KMS-managed keys with HSM protection, and automated PII detection.
Read in the whitepaperIdentity & Access
SAML 2.0 SSO, TOTP multi-factor authentication, scoped API keys, session management, and IP allowlisting.
Read in the whitepaperCompliance
GDPR data subject rights, DPA, TCPA/CASL enforcement, SOC 2-aligned controls, and a HIPAA BAA for healthcare.
Read in the whitepaperOperational Security
Employee background checks, mandatory security training, a documented incident response plan, and responsible disclosure.
Read in the whitepaperDocumentation
Resources for your security team
Everything you need for a vendor review — read online, download, or talk to us.
Security Whitepaper
The full technical overview of our security architecture across all six control domains.
Read onlineWhitepaper PDF
The same document as a PDF — for offline review, compliance files, or your security team.
Download PDFPrivacy Policy
How we collect, use, and protect personal data across the platform and our marketing sites.
Read the policyDPA & Security Reviews
Request our Data Processing Agreement, SOC 2-aligned documentation under NDA, or a security questionnaire review.
Contact usResponsible Disclosure
Found a vulnerability? We work with security researchers under a responsible disclosure program with safe harbor protection. Report issues directly to our security team and we will respond promptly.
[email protected]Have Security Questions?
Schedule a security review with our team. We are happy to walk through our architecture, complete your questionnaires, and share documentation under NDA.