Trust
Security at Clark.
Your business data is sensitive. Here is how we protect it. Last updated: June 14, 2026.
Your data is isolated from every other customer
Clark is multi-tenant, and each customer's data is separated at the database layer with row-level security. One customer's data is never visible to another, and we never mix one customer's data into another customer's dashboard, briefing, or answer.
Encryption
Data is encrypted in transit with TLS and encrypted at rest in our database and storage. Connections to the app and to your data sources run over encrypted channels.
Access controls
Access to your data is role-based and limited to what is needed to run and support the service. Authorization is enforced from trusted server-side identity, not from values a browser can change. Administrative access is restricted and logged.
Built on trusted infrastructure
Clark runs on Supabase and Vercel, providers that maintain independent security certifications such as SOC 2 for their platforms. See our subprocessors for the full list of providers and what each one handles.
Application security
We apply security headers and a content security policy, keep dependencies patched, and maintain an automated security regression suite so that fixes stay fixed. We follow a least-exposure approach to secrets and credentials.
How we handle AI
When Clark generates a briefing or answers a question, the relevant data is sent to our AI providers to produce a response. We work with those providers under terms that prohibit using your business data to train their models, and we never use your data to build models that serve any other customer.
No protected health information
Clark is built to analyze business, financial, and operational data, and is not designed to process Protected Health Information. Please configure your data sources to exclude clinical or health records. See Section 5 of our Terms of Service.
Monitoring and incident response
We log and monitor the service for errors and abuse and maintain an incident response process. If a security incident affects your data, we will notify you without undue delay and provide the information you need, as described in our Data Processing Addendum.
Your controls
You can disconnect a data source at any time, and you can ask us to export or delete your data. See your rights and our retention practices in the Privacy Policy.
Where we are headed
We are continuing to mature our security program, including pursuing a formal SOC 2 audit as we grow. If your team has a security review or questionnaire, we are happy to work through it.
Report a vulnerability
If you believe you have found a security issue, please email clark@kenanali.com and we will respond promptly. Please do not publicly disclose an issue before we have had a chance to address it.