Vol. I · No. 03The ClarifydBroadsheet
Security desk

What we do so you can upload a contract.

You trust us with documents that, in the wrong inbox, would change your cap table. We treat them like that.

[email protected]
01

Your contracts are private

Every contract you upload is scoped to your account. No other Clarifyd user — or staff member — can read your documents.

  • Industry-standard encryption protects data in transit and at rest.
  • Deleted analyses are removed from the dashboard immediately.
  • Each browser session is scoped to the signed-in user.
02

Sign in your way

Use email and password, Google, or Facebook to access your founder account. You stay in control of which credentials are connected.

  • Disconnect a social login at any time from settings.
  • Delete your account and we remove every contract you own.
  • Forgotten password? One-tap email reset.
03

Built for repeat reviews

Re-upload the same contract and we serve the previous analysis instantly. Compare versions side-by-side as you negotiate.

  • Export findings as JSON or PDF for any analysis.
  • Every accepted clause becomes a one-click redline.
04

AI use and zero training

Contracts are sent to Clarifyd AI for reasoning, then cached by SHA-256 so a re-upload of the same contract is byte-identical and free. We do not train, fine-tune, or improve models with customer contract content. Ever.

05

Local storage scoping

The frontend scopes every browser localStorage key by signed-in user via `clarifyd.user-key`. On login or logout we wipe 11 known legacy unscoped keys so a fresh account never sees prior-user data.

06

Operations and access

Production access is two-factor only. Staff cannot read customer contract content unless the customer opens a support ticket and grants read access for a bounded window.

  • Quarterly access audit. Off-boarded staff lose all credentials within one business hour.
  • Backups are encrypted and tested for restore monthly.
Responsible disclosure

Found a vulnerability?

Email [email protected] with a reproduction. We acknowledge within 48 hours. Eligible findings receive credit on this page and a token of thanks.