How we keep your data safe.
GTM Clarity handles conversations and identity data for B2B revenue teams. Here's how we protect it.
Encryption everywhere
All data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Secrets are managed, never hard-coded.
Privacy-first identity
Identity resolution runs on hashed identifiers and is UID2-compliant. We don't sell your visitor data — ever.
Infrastructure
Built on SOC 2 Type II certified vendors — Vercel, Neon, and Clerk. Our own SOC 2 Type II audit is in progress; no report is available yet.
Least-privilege access
Tenant data is isolated per customer. Internal access is role-scoped, logged, and reviewed.
Data handling
We process two kinds of data: conversation data (the chats visitors have on your site) and identity data (firmographic and contact attributes resolved through the delivr.ai identity graph). Conversation data belongs to you. We use it to operate and improve your assistant within your tenant — not to train shared models without consent.
Subprocessors
The vendors that process customer data on our behalf, what each one does, and what it touches:
| Subprocessor | Purpose | Data categories | Region |
|---|---|---|---|
| Vercel | Application hosting, edge/network delivery, deployment logs | Conversation data, Identity data, Account data | US |
| Neon | Managed Postgres database | Conversation data, Identity data, Account data | US |
| Clerk | Authentication, organizations, user profile and session management | Account data | US |
| delivr.ai | Identity resolution (anonymous visitor to known account) | Identity data | US |
| Stripe | Billing, payment methods, invoices, usage-based metering | Account data, Billing data | US |
| Anthropic | AI model inference for chat responses | Conversation data | US |
| AblyActive only when configured | Realtime transport for live agent-visitor handoff | Conversation data | US |
| Embeddings provider (OpenAI or Voyage)Active only when configured | Knowledge-base and corpus embeddings for retrieval | Conversation data, Knowledge-base content | US |
| MailgunActive only when configured | Outbound email delivery for lead notifications, and delivery/bounce events | Conversation data, Identity data | US |
Compliance
GTM Clarity supports GDPR and CCPA data-subject requests. A customer's org admin (or our support team, on request) can export or erase everything we hold about a visitor, fulfilled within 30 days. Destinations you've connected (e.g. Salesforce, HubSpot) are yours to update separately — we never call a third-party delete API on your behalf. See our Privacy Policy for how we collect and use data.
Responsible disclosure
Found a vulnerability? Email security@gtmclarity.ai. We acknowledge reports within two business days and will work with you on a fix and disclosure timeline.