Built to pass your security review

Your taxonomy is the map of how your organization spends. Claravine protects it with audited controls, contractual commitments and the access management your IT team already expects, so security is answered on day one, not negotiated on the last.

Attested, not asserted

Every commitment on this page is backed by a document you can open.

SOC 2 Type II

Independently audited controls for security, availability and confidentiality, tested over time rather than at a point in time. First achieved in 2022, renewed in 2024.

Read the announcement

A Data Security Addendum in every contract

The controls on this page are not a marketing claim. They are Exhibit D of the Master Services Agreement, the terms Claravine is bound to for every customer.

Read the addendum

99.95% availability, in writing

A monthly availability commitment with defined maintenance windows, severity levels and response targets, in the Service Level Agreement.

Read the SLAs

Who gets in, and what they can change

A taxonomy is only governed if the people who can change it are known. Access control is part of the product, not an add-on.

Single sign-on

SAML 2.0 or OpenID Connect through your identity provider, so access follows your directory and ends when IT disables the account. Roles can be assigned from directory attributes, and users are provisioned just in time at first login.

How SSO is set up

Multi-factor authentication

A time-based code from an authenticator app on every login, enabled account-wide so no user can opt out. Users signing in through SSO carry their identity provider's factor.

How MFA works

Role-based access

Permissions by role on a least-privilege, need-to-know basis. No shared accounts; access reviewed at least quarterly.

Approval workflows

A named person between a proposed change and production, with an activity log of who changed what, and when.

Multi-tenant isolation

Your instance and your data are isolated from every other customer's on shared infrastructure.

How your data is protected

The controls Claravine is contractually bound to, in the order a security questionnaire asks about them.

Encryption at rest and in transit

All customer data and every backup containing it, on every network to, from and within the cloud services.

Layered network defence

Segmentation, web application firewalls, a demilitarized zone, and intrusion detection and prevention.

Vulnerability management

A standing programme to find and fix critical and high vulnerabilities, including zero-days.

Secure development

A secure software development lifecycle. Releases are checked against existing integrations first, and any release that could affect your data is announced two weeks ahead.

Incident response

A suspected or confirmed incident affecting your data is reported to you in detail within 24 hours of detection, with remediation at no cost.

Independent audit

The systems and facilities used to process customer data are audited at least annually, on top of the SOC 2 examination.

People

A written information security policy for every employee, background checks where the law permits, and a Chief Information Security Officer accountable for the programme.

Return or destruction

When the contract ends, your data is returned in a portable format or destroyed within 90 days, with certification on request, and every access revoked.

Responsible disclosure

Security researchers who find a weakness can report it and be acknowledged within 24 hours; critical issues are worked to resolution within three days of disclosure.

Read the disclosure policy

Operated to a written service level

Standards can't wait for the platform to come back. The commitments, from the SLAs.

99.95% monthly availability

Excluding scheduled maintenance, with an architecture designed for redundancy.

Critical issues acknowledged within 6 hours

P0, a platform outage or a major security issue, is worked to resolution as soon as possible.

Announced maintenance windows

Saturday evening to Sunday midnight Eastern, two business days' notice, at most eight business hours a month.

Continuity within a day

A tested continuity plan that restores service to SLA within one day of a disaster at the primary site.

Frequently asked questions

Running a vendor review? Bring the questionnaire to a thirty-minute call and we'll work through it with you.

Is Claravine SOC 2 certified?

Yes. Claravine completed its SOC 2 Type II examination in 2022, a year after SOC 2 Type I, and achieved it again in 2024. Ask us for the report.

Where are the security terms in the contract?

In the Data Security Addendum, Exhibit D of the Master Services Agreement, and in the Service Level Agreement. Both are published in full in the legal hub.

Can we use our own identity provider?

Yes. Claravine connects to your identity provider over SAML 2.0 or OpenID Connect and has supported every enterprise provider asked for, including Active Directory and ADFS. You choose whether the directory decides only who gets in, or also which role they hold; users are provisioned at first login and matched to existing accounts by email, so nothing is lost in the switch. The setup guide has the details.

What happens to our data when we leave?

Within 90 days of termination your data is returned in a standard portable format or destroyed, at your option, across production, cloud and backup systems. Claravine certifies the destruction or return, and the revocation of every access, on request.

Do you complete security questionnaires?

Yes. Most of what a questionnaire asks is answered by this page and the addendum; for the rest, contact us and the security team will complete yours.

Bring your security review to the demo

Thirty minutes with someone who has taken Claravine through enterprise procurement, with the SOC 2 report and the addendum on the table.