Trust Center

Trust Center

Trust Center

How we protect your data

Encryption

Customer data is encrypted in transit with HTTPS/TLS and at rest using industry-standard encryption from our cloud infrastructure.

U.S. hosting

Data is stored in Google Cloud Storage in the United States, in a separate storage bucket for each organization.

Access control

Every login uses a one-time passcode, and Firm User, Admin, and Super Admin roles control who can see and do what.

Your documents stay yours

Clasp’s AI features run on metadata and embeddings. Document text and customer data are not sent to external large language models.

Credentials and secrets

Integration tokens and system credentials are kept in an enterprise-grade secrets manager, with access limited to authorized personnel.

Incident response

We acknowledge incident reports within 48 hours and notify affected customers without unreasonable delay once an incident involving their data is confirmed.

Compliance & Frameworks

The certifications and frameworks that guide our security, privacy, and AI governance practices.

SOC 2 Type II

We meet SOC 2 requirements to keep client data secure and compliant across all our systems.

SOC 2

ISO 27001

Certified against the internationally recognized standard for information security management.

ISO 27001

ISO 42001

Our AI governance framework gives clients confidence in how we build and run AI.

ISO 42001

GDPR

We operate under GDPR — the world’s strictest standard for data privacy.

GDPR

Questions about security or privacy?

Email hello@clasplegal.com or write to Clasp Legal Technologies, Inc., 300 Creek View Rd, Suite 209, Newark, DE 19711, United States.