Your numbers are nobody's business but yours.
Before you hand anyone your books, your deal file, or your customer list, you deserve to know exactly how it will be treated. This page is that answer in plain language. The privacy policy carries the full legal version, and nothing here goes an inch past it.
Six commitments, every engagement
Encrypted, both directions
Your data is encrypted in transit and at rest in the systems that hold it. Nothing moves over an open line, and nothing sits in the clear.
Read-only, and yours to revoke
We work from read-only access wherever possible. You grant it narrowly, we never move money or alter your ledger, and you can revoke it any day without a conversation.
Never used to train anything
Your files do your work and nothing else. Client data is never used to train any AI system, ours or anyone else's, and that is a condition we set, not a preference.
A person signs off
Machines do the heavy lifting here, and a human reviews client work before it ships. Nothing generated reaches you, your customers, or your file unread.
Confidential by default
Your deal, your numbers, and your customer list are shared with nobody. We sign a confidentiality agreement on request, before we see anything.
Deleted when you say so
When an engagement ends, we delete or return your data on request and confirm it in writing, keeping only what the law makes us keep.
Where your data actually lives
Mostly where it already lives today: in your own systems. The reporting work runs on accountant-style access to your accounting platform. The AI work runs inside the tools you already use wherever possible, through scoped connections you can see and cut. Deal work runs on documents you choose to send. We do not build a second copy of your business in somebody's warehouse.
Where a platform does hold data in an engagement, it is the boring, heavyweight kind: your accounting system, our payment processor, our scheduling and email providers. Those platforms carry their own independent security attestations, SOC 2 Type II and ISO 27001 among them, and their audit reports are public. We choose them partly for that. Our own practices ride on top and are listed in full in the privacy policy, including the short list of providers we share anything with and why.
The part most firms will not say out loud
We do not paste badges we have not earned. ClarIQ is a founder-run advisory, not a software platform, and it has not sat a SOC 2 audit of its own. The certified systems above are where your data lives; our own controls are the six commitments on this page, in writing, enforceable the old-fashioned way: in the engagement letter you sign.
If your company's requirements call for a formal attestation from every vendor, say so on the first call. We will tell you honestly whether we can meet your bar, and where the work should run inside your own certified systems instead. That answer costs nothing and it is occasionally "we are not the right fit," which is also worth knowing in thirty minutes rather than thirty days.
If you handle patient information
Med spas, clinics, and practices covered by HIPAA get a version of this built for them. Nobody can sell you a "HIPAA certificate"; there is no such thing. Compliance is a way of working, and ours is: patient records stay inside your compliant systems, we take the minimum access that does the job, and where the work allows it we run on de-identified exports instead of raw records. Our med spa reactivation service, for example, is built on a de-identified visit history by design, not as a favor.
If an engagement would touch protected health information directly, we scope that on the call, in writing, with your compliance obligations stated first. If a piece of work cannot be done inside those lines, we say so and do not do it.
What to keep out of forms and chat
Site forms and the chat widget are for questions, not for confidential material. Keep financial records, account credentials, and anything sensitive out of them. Inside an engagement, documents move through private channels we set up together, and your purchase confirmations name the exact method for anything you buy.
Ask us anything about this
Thirty minutes, free. Bring your security questions first if that is what stands between you and handing anyone your numbers. You will get straight answers from the person who does the work.
Book the free 30-minute callOr read the long versions: Privacy policy · Terms · How this firm runs
