Security

Security for governed revenue AI.

Clearskies connects AI to revenue context without creating a shadow access layer. Permissions, security logging, and source-level controls follow your existing data rules.

Trust Center

Clearskies is built by Scratchpad, and our shared Scratchpad Trust Center covers Clearskies security materials. Customers and qualified prospects can request access to SOC 2 Type II documentation, security monitoring, system status, and supporting diligence materials.

Compliance

SOC 2 Type II

SOC 2 Type II

Documentation available

Clearskies is SOC 2 Type II compliant. Customers and qualified prospects can request access through the Trust Center, along with additional security documentation needed for procurement or vendor risk review.

Our data practices are aligned with GDPR and CCPA. A Data Processing Addendum (DPA) is available for customers who require it — view DPA.

For questions that are not covered in the Trust Center, contact security@clearskies.cc.

Data protection

Built around the way your source systems already govern data.

Encrypted data

Customer data is encrypted in transit and at rest, including the data Clearskies uses to build and serve revenue context.

Source-level controls

AI workflows inherit the permissions and source-level controls already present in the systems Clearskies connects to.

Security logging

Governed workflows need visibility. Clearskies is designed so security-relevant access and activity can be reviewed as part of diligence.

Customer data isolation

Each customer's revenue context graph is logically isolated. No customer can access another's data or context.

Data residency

Clearskies production infrastructure is hosted on AWS in US regions. All data is encrypted in transit (TLS 1.2+) and at rest.

AI governance

One governed context layer, not a new connector sprawl.

No model training

Clearskies does not develop or train AI models. Customer data is used to build and serve a governed revenue context layer for authorized workflows, not to train AI models.

Controlled access to context

Clearskies gives AI the context required for approved revenue workflows without asking every AI client to connect directly to every business system.

Model-agnostic by design

Claude, ChatGPT, internal agents, and other tools can use the same governed context layer, reducing drift across tools, users, and prompts.

Diligence path for AI handling

Model-provider handling, retention, and customer-data questions can be reviewed through the Trust Center or directly with the Clearskies security team.

Security resources

What security teams can request.

SOC 2 Type II report and supporting security documentation

Real-time security monitoring and system status

Subprocessor and vendor risk information

Additional artifacts for vendor questionnaires and procurement review

Open Trust Center
Contact

Need something specific for review?

Security teams can request additional documentation, ask about customer data handling, or route vendor risk questions to security@clearskies.cc.

Security reference
CompanyScratchpad, Inc. (operates Clearskies)
CertificationSOC 2 Type II
Audit periodApril 16, 2025 - April 15, 2026
AuditorLinford & Co LLP
InfrastructureAWS (US-based)
ComplianceGDPR-aligned, CCPA-aligned
Customer data trainingNo - Clearskies does not develop or train AI models, and customer data is not used to train AI models.
Data isolationLogically isolated per customer
Data deletionWithin 90 days of valid request
Documentationtrust.scratchpad.com (NDA required)
Subprocessorsscratchpad.com/subprocessors
DPAscratchpad.com/legal/data-processing-addendum
Security contactsecurity@clearskies.cc