generated: '2026-08-04' method: searched probe: true url: https://compliance.clearspeed.com/ platform: SafeBase platform_note: >- The trust center is a SafeBase-hosted portal. Its compliance automation is stated to be Drata. https://trust.clearspeed.com/ is advertised on the marketing security page but did not complete a TLS handshake on 2026-08-04; https://compliance.clearspeed.com/ is the host that actually serves the trust center (HTTP 200). linked_from: https://www.clearspeed.com/security-commitment certifications: - name: SOC 2 Type 2 document: Clearspeed - 2025 SOC 2 Type 2-Schellman.pdf auditor: Schellman year: 2025 access: gated (NDA/request flow on the trust center) - name: ISO 27001:2022 document: ISO 27001_2022_Certificate.pdf access: gated - name: UK Cyber Essentials document: UK Cyber Essentials Certificate.pdf access: gated frameworks_claimed: - ISO 27001 - ISO 27701:2019 - SOC 2 - GDPR - CCPA - HIPAA - NIST 800-53 - NIST 800-171 frameworks_note: >- ISO 27701:2019, HIPAA, GDPR, CCPA, NIST 800-53 and NIST 800-171 are named in trust center control narratives and on the marketing security page as frameworks Clearspeed aligns to or maps controls against. Only SOC 2 Type 2, ISO 27001:2022 and UK Cyber Essentials are backed by a downloadable certificate/report on the portal. control_domains_published: - Access Control - AI Governance - AI Security - App Security - Application Penetration Testing - Asset Management - Audit Logging - Backup - BC/DR - Business Continuity Plan - Change Management - Code Analysis - Configuration Management - Container Orchestration - Continuous Monitoring - Credential Management - Data Retention and Destruction - Penetration Testing - Responsible Disclosure - Software Bill of Materials (SBOM) - Software Development Lifecycle - Subprocessors - Vulnerability & Patch Management infrastructure_disclosed: - Amazon Web Services - Google Cloud - HashiCorp Vault (secrets management, KMS auto-unseal, Kubernetes "Services" clusters) subprocessors: published: partial note: >- A Subprocessors section exists on the trust center but the list is behind the document-request flow — "Please contact us for more details." document_access: public_documents: false flow: request/NDA through the SafeBase portal security_contact: null security_contact_note: >- No security@ address is published on the trust center, on the marketing security page, or in a security.txt (none exists on any Clearspeed host — see well-known/clearspeed-well-known.yml). Reports go through the trust center contact flow. evidence: - {source: 'https://compliance.clearspeed.com/', http_status: 200, keywords: [SOC 2 Type 2, ISO 27001:2022, ISO 27701:2019, HIPAA, GDPR, CCPA, Drata, SafeBase, Trust Center, Responsible Disclosure]} - {source: 'https://www.clearspeed.com/security-commitment', http_status: 200, keywords: [ SOC 2, ISO 27001, GDPR, NIST 800-171, View Clearspeed Trust Center]} - {source: 'https://trust.clearspeed.com/', http_status: null, result: TLS handshake failure} x-evidence: fetched: '2026-08-04' cross_links: vulnerability_disclosure: security/clearspeed-vulnerability-disclosure.yml conformance: conformance/clearspeed-conformance.yml domain_security: security/clearspeed-domain-security.yml