Security


Overview
Security is a top priority at Clearsighted. Our Senior Management team is accountable for security and ensuring that security capabilities and competence exist in all areas of our business.
We’ve built a comprehensive security program that is in line with UK Cyber Essentials and National Cyber Security Centre (NCSC) Cloud Security Principles. As verification of our commitment to security best practices, Clearsighted is certified to UK Cyber Essentials Plus standards. This means we have implemented robust security measures and have also passed a thorough security audit carried out by an independent third party specialist, which included vulnerability scans on both our internal and external infrastructure. According to the UK Government, completing this certification helps organizations to mitigate 80% or more of the most common digital threats. Our UK Cyber Essentials Plus certificate can be supplied on request.
Clearsighted also has strict controls on the information it keeps on its clients and interviewees and is GDPR compliant. This is outlined in our Privacy Policy, which can be found at the end of this document. We also pay the Data Protection Fee outlined by the UK Information Commissioner’s Office (ICO).
As a whole, we follow a holistic approach to guarantee the confidentiality, availability, and integrity of your data, which is split into the following functional areas:
- Security of the infrastructure hosting the Clearsighted app
- Security of the app itself
- Proactive and regular monitoring for security vulnerabilities
- Access and identity management, for both end-users and Clearsighted’s Analysts
- Implementation of security best-practices in-house at Clearsighted, including the provision of devices, and employees’ awareness and behaviour.
On this page, you can read about the various policies and security measures taken by Clearsighted to secure user content and data hosted on our platform from unauthorized access.
Overview of the Clearsighted app
Clearsighted is built on top of a full stack development platform called Bubble.io, and utilizes the robust security features built-in to Bubble to secure the app. Bubble conforms to SOC 2 type II, is penetration tested and meets GDPR (DPA) standards. Certificates can be provided on request.
Bubble – and, by default, the Clearsighted app – is hosted on top of AWS. AWS is compliant with ISO 27001, SOC 2 type II and meets GDPR security standards.
Security research and responsible disclosure
The Clearsighted app and its functionality is developed using the low-code-no-code tools of Bubble.io. Currently, Bubble’s terms of service indicate that it does not allow individual app creators to independently authorize security research programs. We are therefore not able to pay bug bounties at this point in time. However, in the event that we expand our platform beyond Bubble.io and/ or deploy custom code, this may change and at that point we will put in place a responsible disclosure policy, a bug bounty program and a ‘hall of fame.’
In the meantime, security researchers who do wish to bring any security issue to our attention should please email [email protected] with the subject heading of ‘security issue’ and we’ll respond as soon as possible.
The Clearsighted website is outside the scope of any security research activities.
Secure hosting
ISO compliant data centres
Our infrastructure runs purely on Amazon Web Services (AWS), which delivers infrastructure as a service with market leading security capabilities. This means that the Clearsighted app is developed and deployed on a secure and reliable foundation.
The data centres used for storing your content and allowing it to be delivered to your users are certified for compliance with the ISO 27001 standard (the specific datacenter that houses Clearsighted data is within this scope). This standard details requirements for an information security management system (ISMS) within an organization – that is AWS – to ensure they systematically evaluate risks, threats and vulnerabilities to their information security, and have controls and a management process to constantly manage risk and meet security needs. To provide unbiased neutrality, certification is carried out by independent third-party auditors (EY CertifyPoint).
Encryption at rest
Your data is encrypted at rest in AWS S3 buckets, AWS RDS instances and block devices used by AWS EC2 instances. AES-256 encryption is used by default via AWS’ encryption services, while key management is handled by AWS KMS. This means that your data is encrypted in a secure environment in line with industry standards and that the content is safe from prying eyes and manipulation.
Encryption in transit
All communication between you, your services and Clearsighted, that includes your data, traverses the Internet via encrypted HTTPS traffic using TLS. Bubble, and therefore Clearsighted, uses versions 1.3 or 1.2 for all connections. This encryption during communication ensures information cannot be read or manipulated by unauthorized third parties.
Data Sovereignty
Interview data that is uploaded into the Clearsighted app is transmitted to and processed by AWS in the United States (AWS West Region), in line with Bubble.io’s standard hosting terms. Data will therefore be protected by United States laws.
Data sovereignty is discussed further below in a section of our Privacy Policy (see Hosting III.).
Clearsighted has future plans to give clients more granular control over where their data is housed.
Security of the Clearsighted app
Clearsighted is built on top of a full stack development platform called Bubble.io, and utilizes the robust security features built-in to Bubble to secure the app.
Security standards
Bubble conforms to SOC 2 type II, is penetration tested and meets GDPR (DPA) standards. Certificates can be provided on request.
Data Encryption
Data in the app is safeguarded in transit with TLS and at rest with AES-256 encryption through RDS. TLS is used to protect all communication between the app and its servers, including updates. Encryption ensures that data cannot be read or manipulated by unauthorized third parties.
Advanced DDoS protection
Clearsighted uses Bubble.io’s protection against Distributed Denial of Service (DDOS) attacks, which are attacks designed to overwhelm an app’s servers and interrupt service to customers. To provide this DDOS protection, Bubble utilises a combination of its own in-house technology, as well as the services of Cloudflare, which protects many of the world’s top apps and websites.
Vulnerability testing
The Clearsighted app is scanned for 20 different common vulnerabilities, 5 times a month, in line with Bubble’s Starter Plan. Frequency of scans is likely to increase as Clearsighted’s customer base grows.
Additional proactive monitoring
Clearsighted uses AI tools built-in to the Bubble platform to predict the sensitivity of detected vulnerabilities.
As part of its UK Cyber Essentials Plus certification, Clearsighted also has third party independent security specialists Cybaverse scan Clearsighted’s internal and external systems at least once a week to test for vulnerabilities. Cybaverse also provides Clearsighted with a threat management dashboard, which proactively flags vulnerabilities.
Backup and disaster recovery
Clearsighted uses Bubble.io’s backup and disaster recovery policies. Bubble offers both automated and manual backup options for application data.
Bubble uses a system called point-in-time backup, which means that for every change made to the database, a snapshot is saved. This snapshot can then be used later to restore the database to that exact point in time if something should go wrong. This is particularly useful for recovering data in the case of accidental deletion or changes.
Bubble also provides version control for database changes.
In the future, Clearsighted intends to also implement another periodic, off-site backup to guard against low-tech threats such as fire. This will become a priority as the Clearsighted user base grows.
Identity and access management
End-user authentication and access
Users access Clearsighted via the desktop app, once the app has been configured for them by their Clearsighted Analyst.
Users can only gain access using MFA (Multi-Factor Authentication) via email. MFA is a process that requires users to provide two different forms of identification to access the Clearsighted app, providing an additional layer of security beyond just an email username and a password.
To first gain access to the platform, Clearsighted sends a login link to each new user with a temporary password which must be activated within one hour, or else it will expire. On first login, users will have to select a new password.
The Clearsighted app is set to automatically require re-authentication by the same MFA email method after 90 days.
Only Clearsighted Analysts have the ability and the app permissions to add new, or remove old users to/from the Clearsighted app. Adding and removing users is done at the written request (email or chat) of the Client. The exception to this is if Single Sign On (SSO) and/or Directory Sync are enabled.
For clients requiring access for a larger number of users (typically 20 individuals or more), Clearsighted is able to set up Enterprise Single-Sign-On (SSO) or Directory Sync via WorkOS (www.workos.com), which expedites the secure on and offboarding of users. SSO enables users to log in with their company credentials (e.g. [email protected]) without having to enter their password on every single login. Directory Sync synchronizes user data across different platforms, reducing the need to manually administer users; it ensures that, for instance, once a user is removed from a Client’s HR system, their access to the Clearsighted app is also removed. Please speak to your Analyst about this provisioning.
Removal of access
As outlined in Clearsighted’s client contract, if a client wishes not to renew come the contract end date, Clearsighted will permanently delete all client data after a period of 90 days. This includes all login details and access for Client’s users.
On permanent deletion of a Client’s interview repository on the app, Clearsighted staff will also no longer be able to see, or access this information.
Authentication and access of Clearsighted personnel
Each Client’s Clearsighted Analyst[s], who is/are primarily responsible for scheduling, conducting and analysing interviews, will log into the Clearsighted app admin console in order to upload interview results into the Client’s interview repository in the app. A Client’s personnel – i.e. the end-users who want to see/ read/ listen to the interviews themselves – do not have access to this admin ‘back-end’ of the Clearsighted app, and are unable to upload and edit interviews.
Clearsighted Analysts are also subject to MFA, and required to use strong passwords which are generated by an approved password manager (approved by Clearsighted). In line with NCSC and UK Cyber Essentials Plus guidance, frequent changing of passwords is not enforced.
All passwords used by Clearsighted staff, both for access to the Clearsighted app and any other corporate systems, are generated by and stored in password managers.
Principle of least privilege
Clearsighted enforces the principle of least privilege, which means that Clearsighted staff are given the minimum access to the app that is strictly necessary for them to perform their specific job roles.
Security practices implemented in-house
Endpoint security
All devices used by Clearsighted employees are less than 5 years old, running up-to-date OS versions and are configured with ‘second look’ Anti-virus software as well as built-in protections which conduct continuous, ‘real-time’ scanning for threats.
Laptops/ desktops used by Clearsighted staff also have separate admin accounts created, which must be logged into when changes are needed – such as installing new software. This ensures that unauthorized third parties are prevented from accessing or having the ability to make changes to or install malicious programs on Clearsighted’s machines.
All Clearsighted’s machines also have an outbound firewall installed.
Regular, full security scans are run on these devices. These devices have strong passwords and PINs, and are set to lock when they are idle.
Devices no longer being used have their data wiped and then their operating systems reset to default. Additionally, where necessary, storage mediums are physically destroyed to prevent any attempts at data recovery.
Firewalls
All laptop and desktop devices have firewalls, which are set to deny all incoming connections. Clearsighted devices use both inbound, and outbound firewalls in conjunction.
BYOD policy
Clearsighted does not currently operate a BYOD policy, and Clearsighted personnel only access company systems from company owned and controlled devices.
The Clearsighted app is currently desktop only, and not accessible via a mobile app. This removes the possibility that any of Clearsighted’s personnel will access the app from their own, personal mobile device.
Network security
Routers are purchased from vendors with strong security programmes. Router settings are hardened to improve security. Clearsighted uses the strongest available WiFi encryption protocols. We keep router firmware updated regularly.
On Clearsighted’s premises, all devices sit behind hardware firewalls. Our network is segmented into security groups to help prevent lateral movement. All Clearsighted desktops and laptops run VPNs, which protect the devices when using internet connections outside of Clearsighted’s premises.
Behavioural Controls
Clearsighted understands that the majority of cyber attacks take place due to the behaviour of employees. As such, Clearsighted’s employees and contractors are required to be familiar with our Security and Privacy policies, and to undergo regular training in-line with the UK National Cyber Security Centre (NCSC) guidelines. The completion of this training is mandatory, and written into both full-time and temporary employment contracts.
Employee monitoring and exit procedures
Any employees joining Clearsighted, regardless of role, are required to undergo pre-employment background checks. Ongoing employment is conditional, on the expectation that employees continually meet the standards outlined in Clearsighted’s Workplace Conduct document – which includes a section on security awareness, data privacy, and app access.
When an Clearsighted employee leaves the organization, they are required to return all their equipment (usually one laptop or desktop each), wherein their permissions to access Clearsighted systems is permanently revoked.
Privacy Policy
This notice is issued by Clearsighted Ltd (“Clearsighted”, “we”, “us”, and “our”) and explains how we may process your personal data. This notice may be amended or updated from time to time. Please check back regularly for updates. This notice is addressed to individuals outside our company with whom we interact, including customers, site visitors, research participants, and other users of our services (together, “you”). Your privacy is important to us. This Privacy Policy discloses our information practices relating to our website, data collection services, and software tools.
I. Collection and Use of Personal Data
Clearsighted is a consulting and software services provider that carries out data collection and analysis on behalf of our contracted clients to help them understand why they win and lose sales opportunities. We may also carry out competitor research, customer research, or other custom research activities as ‘add on’ services at the request of our customers. In carrying out these services, we may collect or obtain personal data about you, either directly from you (e.g., voluntarily filling out an Onboarding document), in the course of our relationship with you (e.g., voluntarily participating in a win-loss interview), or from our clients. The personal data we capture and store is limited to basic details which may include your name, work email address and company name, as well as any views or opinions you voluntarily share with us via telephone interview and/or web survey. Whenever personal data is acquired directly from you (e.g., voluntarily filling out a website form) Clearsighted will process the data for its own business purposes such as monitoring website activity, responding to requests for information, and/or typical sales and marketing activities to promote our products and services to you. Whenever personal data is acquired indirectly (e.g., transferred from a client in order to facilitate research and analysis) Clearsighted will only process your data for the specific research purposes contracted for by the client.
Thus, all personal data is collected on the basis of either prior consent or the legitimate business interests of our contracted clients in seeking your consent to participate in business-related research activities. There is no material likelihood of any adverse impact on your interest, fundamental rights, or freedoms as a result of the collection and processing of your personal data.
Clearsighted does not collect or process any sensitive personal data, as defined by the UK General Data Protection Regulation (GDPR) and prohibits its clients from sharing sensitive personal information.
II. Protection & Processing of Personal Data
Clearsighted does not sell or share your personal data to/with third parties.
All data is stored and processed with commercially reasonable security measures consistent with industry standards in place to protect against the loss, misuse, and interception of information by third parties. Clearsighted utilizes AWS public cloud servers for its app; AWS holds its physical hosting facilities to these same standards.
Because the internet is an open system, the transmission of information via the internet is not completely secure. Although we will implement commercially reasonable measures to protect your personal data, we cannot guarantee the security of your data transmitted to us using the internet – any such transmission is at your own risk, and you are responsible for ensuring that any personal data that you send to us is sent securely.
Clearsighted also imposes strict internal controls over employees with access to systems used in the storage and processing of personal data. Such access is granted on a “need-to-know” basis only.
Please note that we may disclose your personal data to: legal and regulatory authorities, our contracted clients (e.g., solely with your consent to the client for whom we are conducting the research), any party as necessary in connection with legal proceedings, any party as necessary for investigating, detecting or preventing criminal offenses, and specific third party providers that we may engage to conduct marketing or advertising activities on our behalf. Should this be the case, we take reasonable steps to ensure these third parties have equivalent privacy policies in place.
Clearsighted will not engage a third-party processor to process your personal data. You always have the option to opt out of any commercial activities (see ‘Opt out’ below).
III. Hosting of your data
If you are located in the United Kingdom or the EEA, you should be aware that the personal data you provide to us is being transmitted and processed in the United States. This is because Bubble.io’s hosting provider (AWS – West Region) is located in the US. Your data will be protected subject to this Privacy Policy and United States laws.
Clearsighted is far from the only platform or app to rely on hosting infrastructure which is located in the United States. We use Standard Contractual Clauses (SCCs) – and UK Transfer Addendum and/or Swizz transfer mechanism – to legally transfer and process your data in the US. Both Bubble and AWS have put in place adequate security measures to support this process. Customers searching for more information may wish to look at Bubble.io’s Data Processing Addendum (bubble.io/dpa), or may contact [email protected] with further questions.
While Clearsighted replies on SCCs, it is also worth noting that AWS is certified under the UK Extension to the Data Privacy Framework (also known as the ‘UK-US Data Bridge.’) This framework allows for the transfer of personal data from the UK to the US under the same principles as the EU-US Data Privacy Framework. AWS, as part of Amazon.com, has self-certified to both the EU-U.S. Data Privacy Framework (DPF) and the UK extension, meaning it meets the requirements for transferring data under the UK-US Data Bridge.
IV. Data Retention & Erasure
We take every reasonable step to ensure that your personal data is only retained for as long as it is needed for the performance of our contractual obligations, to make our services available to you, for us to comply with our statutory obligations resulting from applicable laws, and to fulfil the purposes outlined in this Privacy Policy, at which time we will either (i) permanently delete or destroy the relevant personal data, or (ii) anonymize the relevant personal data.
You have many rights relating to your personal data that we store and process, including:
- The right not to provide personal data (e.g., we will always provide a conspicuous opt-out capability with research requests, which may include an Clearsighted Analyst asking if you would prefer to give an interview anonymously).
- The right of access to your personal data;
- The right to request rectification of inaccuracies;
- The right to request the erasure, or restriction of processing, of your personal data;
- The right to object to the processing of your personal data;
- The right to have your personal data transferred to another controller;
- The right to withdraw consent; and,
- The right to lodge complaints with data protection authorities.
We may require proof of your identity before we can give effect to these rights. To make any request, relating to these rights, please direct your specific request to [email protected].
Some requests may require the confirmation of additional facts and we will investigate your request reasonably promptly, before deciding what action to take.
IV. Cookies and Similar Technologies
When you visit our website we may place cookies onto your device, or read cookies already on your device, subject always to obtaining your consent, where required, in accordance with applicable law. We use cookies to record information about your device, your browser and, in some cases, your preferences and browsing habits. We may process your personal data through cookies and similar technologies. For further information, visit allaboutcookies.org.
V. Opt Out
We may process your personal data in order to contact you via email, telephone, direct mail, or other communication formats to invite you to participate in research on behalf of our clients. You can always unsubscribe (e.g., opt out) of any communications by replying to the sender with ‘unsubscribe’ in the subject line.
After you unsubscribe, we will no longer contact you. In the event that another client legitimately provides us your personal data and requests we contact you, you will not be re-contacted (Clearsighted considers ‘opting out’ to be permanent, unless explicitly informed otherwise by you).
VI. General Data Protection Regulation (GDPR)
As has been outlined herein, Clearsighted complies with UK GDPR requirements and values these regulations as important frameworks for establishing data privacy. As such, Clearsighted applies the same privacy practices to all personal data captured on behalf of all users globally.
In compliance with GDPR, these are our legitimate business purposes within which we may process your data:
- Marketing, including newsletters, blogs, guides and product updates
- Advertising, prospecting and sales
- Community-building activities, such as invites to forums, events or webinars
- Conducting win/loss and other interviews
As a ltd company registered in the UK, Clearsighted also pays the annual Data Protection Fee to the Information Commissioner’s Office (ICO).
vii. Further Confidentiality Measures
Clearsighted employees understand that the data they gather about how their clients go-to-market – primarily, why they win and lose deals – is highly confidential. As such, employees and contractors joining Clearsighted are required to sign an NDA that states they will not discuss any findings from a client engagement with any party outside Clearsighted. Even then, internal discussions only happen within project teams at Clearsighted that have a need to know – for example, Clearsighted employees workshopping together how to improve detail gathered from interviews or to deliver additional value for clients.
Clearsighted maintains NDAs with all its clients.

