Security and Compliance
At Clearspot Artificial Intelligence, we take security, compliance, and the protection of our customers’ data very seriously. We are committed to securing your data and earning your trust. We use a variety of industry-standard technologies and best practices to secure our customers’ data. To ensure we’re building trust among our customers, we consider it paramount to achieve the highest standards when it comes to security.
Â
As a company, we value transparency as a core principle and share details about how we handle security at Clearspot Artificial Intelligence. If you have any questions regarding security, we are happy to answer them at info@clearspot.ai.
GDPR
Clearspot Artificial Intelligence is committed to complying with the General Data
Clearspot Artificial Intelligence is committed to complying with the General Data Protection Regulation (GDPR). We have a dedicated security and privacy program and work diligently to follow guidance from privacy-related regulatory bodies in the EU to incorporate any regulation changes.
Â
Because of our commitment to the privacy and security of all our customers’ data, we have applied the privacy and security controls necessary for GDPR compliance across the board to all Clearspot Artificial Intelligence customers at no additional cost.
Â
For customers processing information on behalf of EU and Swiss citizens, Clearspot Artificial Intelligence offers a Data Processing Addendum. Clearspot Artificial Intelligence is a processor of your customer’s data, and you are the controller. To make sure that you are in compliance, you should take the following steps:
Â
- Perform your own research and seek legal advice on how GDPR regulations apply to your business.
- Contact info@clearspot.ai for additional information.
- Update your EU contact details in Clearspot Artificial Intelligence in your account settings.
- Accept the latest Terms and Conditions and Privacy Policy within your account settings in Clearspot Artificial Intelligence.
Â
Infrastructure Security
Physical Access
Clearspot Artificial Intelligence hosts its data in Amazon Web Services (AWS) and Google Cloud. Its employees do not have physical access to Amazon or Google data centers, servers, network equipment, or storage.
Â
AWS provides physical data center access only to approved employees. All employees who need data center access must first apply for access and provide a valid business justification. These requests are granted based on the principle of least privilege, where requests must specify to which layer of the data center the individual needs access, and are time-bound. Authorized personnel review and approve requests, and access is revoked after the requested time expires. Once granted admittance, individuals are restricted to areas specified in their permissions.
Â
Data Residency / Regionalization
Several privacy regulations require localizing regulated data, such as personal information, within a particular region or country (e.g., Australia, EU/UK). To meet this need, Clearspot Artificial Intelligence offers the option to store and process data exclusively within secured data centers located in South Korea, the United Kingdom, and Australia. This includes the imagery provided by the customers, processed data, and the generated assets.
Â
All data for processing or display is uploaded to a Google Cloud Storage bucket located in the customer’s local region. From here, the data is transferred, with encryption, to Google Cloud servers in the customer’s local region for processing. Any outputs resulting from processing, such as maps or models, are pushed to a Google bucket in the customer’s local region. Metadata and other data entered into the platform are stored in databases located on a US-based server.
Â
Please note that all customer data is stored in US data centers unless explicitly agreed upon in the customer contract. Please work with your Clearspot Artificial Intelligence customer success and account executive team to learn more.
Â
Application Security
Login Security
In addition to password-based logins, Clearspot Artificial Intelligence provides Google single sign-on for all accounts, allowing you to use Google or GSuite accounts to authenticate users requiring two-factor authentication (2FA). Google logins can be protected by multiple 2FA mechanisms, including access codes or security keys.
Â
Product Security
Clearspot Artificial Intelligence adheres to the principles of security and privacy by design through our Secure Development Lifecycle. We incorporate key components from industry-standard Security Development Lifecycle models such as the Microsoft Security Development Lifecycle and OWASP Software Application Maturity Model.
Â
Clearspot Artificial Intelligence’s software design phase introduces security and privacy considerations at every stage, ensuring robust protection against potential threats.
If you want Clearspot Artificial Intelligence to delete your account, please send an email to info@clearspot.ai. You must provide Clearspot Artificial Intelligence with reasonable identity verification details prior to us processing any deletion requests. Clearspot Artificial Intelligence is not liable in connection with any deletion requests or if your identity cannot be sufficiently verified in Clearspot Artificial Intelligence’s sole discretion.