ClariDuty trust centre · V2 operational

Clear controls. Honest assurance boundaries.

Our current security, privacy and resilience position is stated plainly so buyers can distinguish operational controls from work that still requires independent assurance.

Privacy by control

Customer records are limited by organisational access and used to provide the service, respond to enquiries and maintain accountable operations.

Human accountability

Automated support does not replace competent approval for legal, safety-critical, clinical or other high-consequence decisions.

No invented badges

Certification, uptime and security claims are published only when evidence exists. A shiny logo is not a control.

Current platform architecture

Production runtime and historical baseline are kept separate.

The current ClariDuty Sites deployment uses a Cloudflare-compatible Vinext application, D1 relational storage and R2 evidence storage. Older GitHub documentation describing the former Next.js, Express, Prisma and PostgreSQL-oriented baseline is historical architecture—not the authoritative description of the current production runtime.

Product status discipline

Working foundations are not presented as complete provider services.

Operational foundation

ClariDuty Connect

Channels, direct and record-linked conversations, threads, mentions, files, reactions, search, broadcasts, acknowledgements, external meeting links, polls, canvases and governed workflow requests are implemented. Native carrier-grade voice, video and screen sharing require a licensed media provider. Automatic AI summaries and translation must not be claimed unless separately configured and verified.

Operational indicator

Universal Compliance Matrix

The matrix calculates tenant-scoped evidence indicators from connected records across displayed frameworks. It supports readiness review; it is not a clause-conformity decision, accredited assessment, certification or guarantee of legal compliance.

Assurance register

What is operational today.

Operational

Customer separation

Organisation-scoped access and tenant-filtered records keep each customer workspace separate.

Operational

Authentication and roles

Authenticated access, founder controls and role-based management permissions protect restricted functions.

Operational

Evidence integrity

Protected uploads, sequential versions, SHA-256 integrity hashes and controlled downloads support defensible evidence.

Operational

Audit history

Material record actions retain the actor, timestamp, entity and decision detail for accountable review.

Operational

Data portability

Tenant-scoped CSV and JSON exports support customer reporting and controlled data extraction.

Operational

Trial retention controls

Expired trials move to export-only access before a controlled retention review, as described in the privacy notice.

Operational

Service readiness probes

V2 health and readiness endpoints test core database availability and clearly identify optional degraded capabilities.

Operational

Custom-domain routing and TLS

clariduty.pro and the Sites deployment route to the same authenticated application. Domain and TLS configuration are active.

Manual verification required

Authenticated custom-domain click-through

Automated cloud-browser verification cannot retain the required signed-in session. This is a client limitation, not evidence of an application defect; the owner must complete the final signed-in check.

Operational

Restricted commercial analytics

Founder-only login, trial-expiry and conversion analytics use authenticated server-side access and private no-store responses.

Planned

Independent penetration test

Independent security testing evidence is not yet published and must be completed before an enterprise assurance claim.

Not certified

ISO 27001 certification

ClariDuty is not currently ISO 27001 certified. Alignment work must not be described as certification.

Not certified

SOC 2 report

ClariDuty does not currently publish an independent SOC 2 report.

Not assessed

HIPAA

HIPAA applicability and compliance have not been independently assessed; ClariDuty should not be represented as HIPAA compliant.

SOC 2 readiness register

Controls mapped. Independent report not yet issued.

ClariDuty now exposes an honest Trust Services Criteria readiness view. This is an internal control-mapping aid—not SOC 2 certification, an attestation report or evidence that every control has operated effectively for an auditor's review period.

Control foundations active

Security

Tenant isolation, role-based access, session controls, protected evidence and audit history are implemented and require continuing operational evidence.

Evidence collection active

Availability

Health and readiness probes support service monitoring. Formal availability commitments and independently sampled evidence remain contractual and audit work.

Control foundations active

Confidentiality

Tenant-scoped access, controlled exports and evidence permissions support confidentiality; customer data classification and contract scope still require review.

Control foundations active

Processing integrity

Governed workflows, validation, revisions and independent verification support processing integrity. They do not replace an auditor's operating-effectiveness tests.

Control foundations active

Privacy

Privacy notices, retention states, access controls and tenant export functions support privacy governance; legal review and evidence sampling remain outstanding.

Buyer due diligence

Prospective customers should confirm contractual terms, data categories, retention, access roles, migration, incident response, backup arrangements, service availability and any sector-specific requirements before production use.

Service termsPrivacy noticeDPA availabilityRequest a due-diligence discussion