Claremont SecurityManaged compliance ยท Enterprise AI protection
// Our_Own_Posture

Security & Trust

A security firm should be willing to describe its own posture in public. This page is that description: how this site is built, where your data goes, and who we rely on. If you are evaluating us, hold us to it.

We are asking firms to trust us with their security posture. Here is why that is reasonable.

// Trust_01

The architecture, in one paragraph

This site is a static application served over TLS from Vercel's edge network, with three serverless functions: one handles form submissions, one records the page-view log described below, and one reads that log back for us. There is no CMS to compromise, no plugin ecosystem, no server we maintain by hand. The interactive tools run entirely in your browser by design, which means the most common way for a website to leak visitor data, sending it somewhere, simply does not apply to them. The site around those tools does keep a visit log, and this page says exactly what is in it.

// Trust_02

How your data moves

Free tools: processed locally in your browser, transmitted nowhere. Nothing you paste into the Clean Room, the WISP tools, the readiness check or the notice tools is sent to us or to anyone else. Every page you open: logged. A small script reports the page, the referring page, the title, your language, time zone and screen size, how long you stayed, a random per-session identifier, your browser and operating system, your IP address, and the approximate country, region and city Vercel derives from it at the edge. That row goes to the same private Supabase database. It is how we know whether anyone reads this. Contact and report submissions: verified by Cloudflare Turnstile, processed by our serverless function, delivered as email via Resend, and recorded in a private Supabase database (United States region) accessible only server-side; the database enforces row-level security with no public read or write access. Vault accounts: authenticated by Clerk; saved prompts and briefings are stored per-account and are not readable by other users.

// Trust_03

Controls we run on ourselves

Transport security with HSTS on every response. Bot and abuse controls on every form: Cloudflare verification, honeypots, timing gates, size caps, and input sanitisation against header injection. Secrets held as server-side environment variables, never in page code, and rotated when exposure is suspected. Least-privilege service keys: the browser-side database key can do nothing the row-level security policies do not explicitly allow. Deployments are versioned through source control, so every change to this site has an author and a history.

// Response_headers, on every page, set in vercel.jsonStrict-Transport-Security: max-age=63072000; includeSubDomains; preloadX-Content-Type-Options: nosniffX-Frame-Options: SAMEORIGINReferrer-Policy: strict-origin-when-cross-originContent-Security-Policy: object-src 'none'; base-uri 'self'; frame-ancestors 'self'; upgrade-insecure-requests
We add providers reluctantly, because every additional vendor is additional surface.

// Trust_04

Providers we rely on

We keep the list short and each provider scoped to one job:

HostingVercelFor hosting, serverless execution and the edge geography in the visit log.
VerificationCloudflareFor Turnstile verification.
DatabaseSupabaseFor the database.
Sign-inClerkFor vault authentication.
EmailResendFor transactional email.
AnalyticsPlausibleFor cookieless page-view counts.
TypefacesGoogle FontsFor the two typefaces this site loads.
MailboxGoogle WorkspaceFor our own mailbox.
SchedulingCalendlyFor scheduling you choose to initiate.

Your browser requests the fonts directly from Google, so Google sees that request. We add providers reluctantly, because every additional vendor is additional surface, and we removed one in September 2026: visitor IP addresses used to be sent to a third-party geolocation service over plain HTTP, and are not sent anywhere now.

// Trust_05

What we do not do

No advertising trackers. No sale or sharing of inquiry data. Our page-view counts identify no one. Our own visit log records your IP address and approximate location, described on the Privacy page, and is never shared or used for advertising. No AI training on anything you submit. No claims of certifications we do not hold: we are a small firm and we describe our posture plainly rather than borrowing acronyms.

// Trust_06

Found something?

If you believe you have found a security issue on this site, tell us at support@claremontsecurity.com with enough detail to reproduce it. We respond to good-faith reports quickly, we will not pursue action against good-faith research, and we credit reporters who want credit.