NEW: See how Lager 157 hit 98–99.8% stock accuracy with Clarity Store. Read the story →
See Clearly. Sell More.

The controls, written down and owned.

A security questionnaire is easier to answer when the answers already exist. This is the policy set behind the platform — what each one governs, who it applies to, and when it was last reviewed. The certification timeline is on the compliance page; this is what is in place regardless of it.

Every policy below is published, version-controlled, and on an annual review cycle.

01The register

Every policy, by what it governs.

An information security management system is only as real as the documents under it. These are published and approved, not drafts.

Protecting the data
  • Information Security Policy the overarching policy every other one sits under
  • Encryption Policy which data, devices and media must be encrypted, and to what standard
  • Data Classification Policy sensitivity levels, and the handling each one requires
  • Data Protection Policy the principles governing processing of personal data
  • Data Retention Policy retention and secure deletion, aligned to UK and EU GDPR
Controlling access
  • System Access Control Policy access granted on documented business need, managed across the full user lifecycle
  • Password Policy how credentials are created, managed and when they are required
  • Network Security Policy deployment and operation of network controls
  • Physical Security Policy controls, monitoring and removal of physical access
  • Acceptable Use Policy what the platform, devices and network may be used for
Finding problems early
  • Vulnerability Management Policy continuous scanning, with severity-based remediation SLAs
  • Logging and Monitoring Policy audit trails kept so an incident can be investigated after the fact
  • Risk Management Policy how risks are identified, assessed and mitigated
  • Change Management Policy changes planned and communicated rather than discovered
  • Software Development Lifecycle Policy security built into how the product is made
When something goes wrong
  • Information Security Incident Response Policy identification, escalation by severity, and notification obligations
  • Incident Response Plan the procedure the policy requires
  • Backup Policy what is backed up, how often, and how restoration is tested
  • Disaster Recovery Plan how service is restored after an unplanned event
  • Business Continuity Plan how the business keeps operating while that happens
Third parties and assets
  • Vendor Management Policy due diligence and risk assessment before a vendor touches customer data
  • Asset Management Policy assets tracked from acquisition through to disposal
  • Artificial Intelligence Policy how AI systems are selected, used and overseen, including privacy and transparency controls
Governance and people
  • ISMS Plan how the management system is established, operated and improved
  • Code of Conduct the human half of an ISMS
  • Disciplinary Policy what happens when it is ignored
  • Recruitment and Selection Policy who gets access to any of it in the first place
02In practice

What that means for your data.

Encrypted

In motion and at rest, across the platform and its interfaces. Covered by the Encryption Policy, with the standards and the media it applies to written down rather than assumed.

Encryption Policy · annual review
Least privilege

Role-based access that reaches into the product itself rather than stopping at the login, granted on documented business need and reviewed across the user lifecycle.

System Access Control Policy · annual review
Recoverable

Backups taken on a defined schedule and restoration exercised, with continuity and disaster recovery planning documented rather than improvised on the day.

Backup Policy, DR and BC Plans

Independent assurance is a separate question from controls, and it has its own page: where SOC 1, SOC 2 and ISO 27001 stand →

03Working with us

Reporting something, or asking for proof.

Two routes, both of which reach a person rather than a queue.

Report a vulnerability

If you believe you have found a security issue in the platform or on this site, write to info@clarityrfid.com with enough detail to reproduce it. We will confirm receipt, triage against the severity SLAs in the Vulnerability Management Policy, and tell you what we found.

Please give us a reasonable window to remediate before publishing.

Request documentation

Policy documents, completed security questionnaires, and the current status of the SOC and ISO engagements are available to customers and to prospects under evaluation. Ask and we will send what we can, with an NDA where the document needs one.

A security review does not have to wait for a contract.

Send us the questionnaire.

Most of the answers already exist in the documents above. Send yours and we will fill it in properly, rather than asking you to take a web page as evidence.