GTMClarity
Security

How we keep your data safe.

GTM Clarity handles conversations and identity data for B2B revenue teams. Here's how we protect it.

Encryption everywhere

All data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Secrets are managed, never hard-coded.

Privacy-first identity

Identity resolution runs on hashed identifiers and is UID2-compliant. We don't sell your visitor data — ever.

Infrastructure

Built on SOC 2 Type II certified vendors — Vercel, Neon, and Clerk. Our own SOC 2 Type II audit is in progress; no report is available yet.

Least-privilege access

Tenant data is isolated per customer. Internal access is role-scoped, logged, and reviewed.

Data handling

We process two kinds of data: conversation data (the chats visitors have on your site) and identity data (firmographic and contact attributes resolved through the delivr.ai identity graph). Conversation data belongs to you. We use it to operate and improve your assistant within your tenant — not to train shared models without consent.

Subprocessors

The vendors that process customer data on our behalf, what each one does, and what it touches:

SubprocessorPurposeData categoriesRegion
VercelApplication hosting, edge/network delivery, deployment logsConversation data, Identity data, Account dataUS
NeonManaged Postgres databaseConversation data, Identity data, Account dataUS
ClerkAuthentication, organizations, user profile and session managementAccount dataUS
delivr.aiIdentity resolution (anonymous visitor to known account)Identity dataUS
StripeBilling, payment methods, invoices, usage-based meteringAccount data, Billing dataUS
AnthropicAI model inference for chat responsesConversation dataUS
AblyActive only when configuredRealtime transport for live agent-visitor handoffConversation dataUS
Embeddings provider (OpenAI or Voyage)Active only when configuredKnowledge-base and corpus embeddings for retrievalConversation data, Knowledge-base contentUS
MailgunActive only when configuredOutbound email delivery for lead notifications, and delivery/bounce eventsConversation data, Identity dataUS

Compliance

GTM Clarity supports GDPR and CCPA data-subject requests. A customer's org admin (or our support team, on request) can export or erase everything we hold about a visitor, fulfilled within 30 days. Destinations you've connected (e.g. Salesforce, HubSpot) are yours to update separately — we never call a third-party delete API on your behalf. See our Privacy Policy for how we collect and use data.

Responsible disclosure

Found a vulnerability? Email security@gtmclarity.ai. We acknowledge reports within two business days and will work with you on a fix and disclosure timeline.