Security

What Clearlist does with the data you send it, how it is protected, and what it keeps. Written for the person filling in a vendor questionnaire. The due-diligence summary covers data sources and method; this page covers handling and infrastructure.

What we receive

Subjects to screen: wallet addresses, names with optional date of birth, nationality or identifier, country codes, and transaction pairs. Optional metadata you attach (for example your own user id) is stored with the decision so you can find it later. We never ask for documents, selfies, bank details or private keys, and the API has no field for them.

Addresses are not secret but names can be personal data. Send only what the screen needs. A name without a date of birth or nationality is matched more loosely and routed to review more often, so sending the corroborating fields is both more accurate and more private: it lets a clear-cut non-match be closed without a human reading it.

API keys

Keys are generated server-side and shown once. We store the SHA-256 hash and the first twelve characters, never the key. A lost key is revoked and replaced; it cannot be recovered. Live and test keys are separate, and decisions made with a test key are tagged so they can be filtered out of your records.

Every request is rate-limited per key; limits are listed on each plan.

Decisions are append-only

A decision is written once with the exact list batch versions, policy version and evidence used, and is never updated. Reviews, allowlist entries and policy changes are separate records that reference it. That is what makes an exported decision usable as evidence: it is the record as it was made, not as it was later edited.

Retention: decisions on the Free plan are deleted after 30 days by a daily job. On paid plans they are kept for the life of the account and deleted when the account is closed. Exposure results are cached for six hours and then discarded.

Encryption and hosting

All traffic is TLS; plain HTTP is not served. The API and dashboard run on Vercel; the database is a managed Postgres service with encryption at rest and automated backups. There are no servers we administer by hand. Secrets live in the hosting provider's environment configuration, never in the repository.

The free address checker at /check stores nothing: the query is not logged and the result is not persisted.

Data sources and third parties

Screening data comes from the publishers: the US Treasury (OFAC), the European Union, the UK OFSI and the United Nations, fetched directly and versioned. Public chain labels come from cited public sources. We use no dataset with non-commercial terms and no resold commercial data.

Counterparty exposure queries chain data providers (Solana RPC or Helius for Solana, Etherscan for EVM chains) with the address being screened. No customer metadata leaves our systems; providers see a public address and nothing else.

Outbound email (the weekly digest and account mail) is sent through a transactional email provider and contains no screening subjects, only counts and list names.

Webhooks

Each endpoint has its own secret, shown once. Deliveries are signed with HMAC-SHA256 over the raw body; verify the signature before trusting the payload. Failed deliveries are retried up to 5 times with backoff starting at 1 minute and ending at 12 hours, and every attempt is visible in the dashboard.

Availability and freshness

Government lists are refetched daily and after every publisher change; a list older than 36 hours is shown as stale on the status page and in the health endpoint. If a provider is slow, exposure degrades to “unavailable” inside its time budget and the screen still returns; the list check never depends on a third party at request time.

Access and operations

Dashboard access is per organisation; members see only their organisation's decisions. Staff access to production data is limited to the operators named on the due-diligence summary and used only for support you ask for or for incident response. There is no sales or analytics use of customer screening data.

Certifications

SOC 2 is planned and not yet audited. Until then this page, the due-diligence summary and the public status history are what we can show. We will not claim a certification we do not hold.

Reporting a vulnerability

Email security@clearlist.xyz. We acknowledge within two business days, keep you informed, and credit you if you want. Please do not test against other customers' data; use a free account of your own.