Trust and Security
The questions your compliance officer will ask
Most firms find out what their compliance team requires after the website is built. By then it is a rework. We ask first, and the platform your system runs on is built to answer.
The four questions
Asked in Discovery, not at launch
Who can see our data?
Access is controlled at the workspace level, and single sign-on can be integrated and enforced. Access follows the identity system your firm already uses, not a separate password nobody manages.
Is access recorded?
Workspace-level audit logs and monitoring are available on every build we run. If someone opens something, there is a record that they did, and that record is there when you ask for it.
Can we restrict who reaches it?
IP allowlisting is available, so access can be limited to your firm's own addresses. Anyone outside that range never reaches the front door in the first place.
Where does our data live?
Data residency can be specified, so where your data sits is a decision rather than a default. It is one of the things we settle in Discovery, not after launch.
The platform underneath
Enterprise-grade where it counts, boutique where you feel it
- SOC 2 Type 2
- ISO 27001
- GDPR
- Data residency
- Audit logs
- Single sign-on
- IP allowlisting
- 99.9% uptime SLA
Where the certifications sit
Clarity Systems Lab is a small studio, and the certifications are the platform's.
We do not hold our own SOC 2 report, and we would rather say that plainly than let you assume otherwise. What we do hold is an enterprise agreement with a platform that does, and the judgment to scope which of its controls your firm actually needs.
The systems we build run on an enterprise development platform that is SOC 2 Type 2 compliant, ISO 27001 compliant, and GDPR compliant, with a 99.9% uptime commitment backed by a service level agreement.
SOC 2 Type 2
Independently audited controls over security, availability, and confidentiality.
ISO 27001
A certified information security management system, reviewed on a recurring cycle.
GDPR
Data handling aligned with the strictest general privacy regime in force.
99.9% uptime SLA
An uptime commitment backed by a service level agreement, not a best effort.
The comparison
Ask the same four questions of anyone else you are considering
Many people building websites for advisory firms work on consumer website builders, where there is one shared login and no audit trail. That is not a criticism of their craft, and for a restaurant it is the right tool. For a firm holding client financial data and answering to a regulator, the four questions above tend to land on a pause.
After launch, someone is watching
Every system we build reports its health to a central monitor every five minutes. That is our own instrumentation, not the platform's, and it is how we find out something has broken before you do.
That watch is part of the build, not an add-on. It stays on for as long as the system runs.
The honest limits
We do not handle protected health information, on any platform, for any client. We are not an investment adviser, an accounting firm, or a law firm. And a certification held by a platform is not a substitute for your own compliance program. It is one input to it.
If your compliance team has a questionnaire, send it. We would rather answer it before you sign than after.
Is your website a working business system?
Take the free Clarity Audit. Answer 10 questions and we'll score your site across Narrative Clarity, Differentiation, Trust Signals, Conversion Path, and Technical Foundation, with a personalized AI report and specific recommendations for your firm.
2 minutes
10 quick multiple-choice questions
AI-personalized
Tailored to your firm and niche
PDF report
Scores + 5 actionable recommendations