Customer records are limited by organisational access and used to provide the service, respond to enquiries and maintain accountable operations.
ClariDuty trust centre · V2 operational
Clear controls. Honest assurance boundaries.
Our current security, privacy and resilience position is stated plainly so buyers can distinguish operational controls from work that still requires independent assurance.
Automated support does not replace competent approval for legal, safety-critical, clinical or other high-consequence decisions.
Certification, uptime and security claims are published only when evidence exists. A shiny logo is not a control.
Current platform architecture
Production runtime and historical baseline are kept separate.
The current ClariDuty Sites deployment uses a Cloudflare-compatible Vinext application, D1 relational storage and R2 evidence storage. Older GitHub documentation describing the former Next.js, Express, Prisma and PostgreSQL-oriented baseline is historical architecture—not the authoritative description of the current production runtime.
Product status discipline
Working foundations are not presented as complete provider services.
ClariDuty Connect
Channels, direct and record-linked conversations, threads, mentions, files, reactions, search, broadcasts, acknowledgements, external meeting links, polls, canvases and governed workflow requests are implemented. Native carrier-grade voice, video and screen sharing require a licensed media provider. Automatic AI summaries and translation must not be claimed unless separately configured and verified.
Universal Compliance Matrix
The matrix calculates tenant-scoped evidence indicators from connected records across displayed frameworks. It supports readiness review; it is not a clause-conformity decision, accredited assessment, certification or guarantee of legal compliance.
Assurance register
What is operational today.
Customer separation
Organisation-scoped access and tenant-filtered records keep each customer workspace separate.
Authentication and roles
Authenticated access, founder controls and role-based management permissions protect restricted functions.
Evidence integrity
Protected uploads, sequential versions, SHA-256 integrity hashes and controlled downloads support defensible evidence.
Audit history
Material record actions retain the actor, timestamp, entity and decision detail for accountable review.
Data portability
Tenant-scoped CSV and JSON exports support customer reporting and controlled data extraction.
Trial retention controls
Expired trials move to export-only access before a controlled retention review, as described in the privacy notice.
Service readiness probes
V2 health and readiness endpoints test core database availability and clearly identify optional degraded capabilities.
Custom-domain routing and TLS
clariduty.pro and the Sites deployment route to the same authenticated application. Domain and TLS configuration are active.
Authenticated custom-domain click-through
Automated cloud-browser verification cannot retain the required signed-in session. This is a client limitation, not evidence of an application defect; the owner must complete the final signed-in check.
Restricted commercial analytics
Founder-only login, trial-expiry and conversion analytics use authenticated server-side access and private no-store responses.
Independent penetration test
Independent security testing evidence is not yet published and must be completed before an enterprise assurance claim.
ISO 27001 certification
ClariDuty is not currently ISO 27001 certified. Alignment work must not be described as certification.
SOC 2 report
ClariDuty does not currently publish an independent SOC 2 report.
HIPAA
HIPAA applicability and compliance have not been independently assessed; ClariDuty should not be represented as HIPAA compliant.
SOC 2 readiness register
Controls mapped. Independent report not yet issued.
ClariDuty now exposes an honest Trust Services Criteria readiness view. This is an internal control-mapping aid—not SOC 2 certification, an attestation report or evidence that every control has operated effectively for an auditor's review period.
Security
Tenant isolation, role-based access, session controls, protected evidence and audit history are implemented and require continuing operational evidence.
Availability
Health and readiness probes support service monitoring. Formal availability commitments and independently sampled evidence remain contractual and audit work.
Confidentiality
Tenant-scoped access, controlled exports and evidence permissions support confidentiality; customer data classification and contract scope still require review.
Processing integrity
Governed workflows, validation, revisions and independent verification support processing integrity. They do not replace an auditor's operating-effectiveness tests.
Privacy
Privacy notices, retention states, access controls and tenant export functions support privacy governance; legal review and evidence sampling remain outstanding.
Buyer due diligence
Prospective customers should confirm contractual terms, data categories, retention, access roles, migration, incident response, backup arrangements, service availability and any sector-specific requirements before production use.