# Trust Center *Trust* > The CommerceClarity Trust Center states what happens to a retailer’s catalog data. CommerceClarity is certified to ISO/IEC 27001:2022 and compliant with the GDPR, with EU data residency available. Product data is encrypted in transit and at rest, access is least-privilege with SSO and SAML, sub-processors are scoped, and no customer data trains shared or third-party models. The certificate, the DPA, the sub-processor list and the security policy are all requestable. Your catalog data stays yours. Here is how we protect it, what we are certified against, and who to ask when you need more information. **Contact email:** security@commerceclarity.com ## Certified and compliant *Compliance* - ISO/IEC 27001:2022 · Certified - GDPR · Compliant, EU data residency available ## How we protect your data - Encrypted everywhere · Data is encrypted in transit (TLS 1.2+) and at rest (AES-256). - Least-privilege access · Role-based access, SSO/SAML, and audited internal controls. - EU data residency · Choose where your catalog data is stored and processed. - No training on your data · Your product data is never used to train shared or third-party models. - Monitoring and logging · Continuous monitoring, alerting, and a full audit trail of every run. - Nothing publishes without approval · Your rules score every output. A human reviews anything uncertain, and nothing reaches your catalog without approval. ## You stay in control *Your data* - You own your data · Your catalog data is yours. We process it to do the job and nothing else. - Scoped sub-processors · A short, published list of sub-processors, each under a strict DPA. - Deleted on request · Export or delete your data at any time. We honor retention windows you set. ## Questions we get asked ### Do you train AI models on our catalog data? No. Your product data is never used to train shared or third-party models. It is processed only to run the jobs you ask for. ### Where is our data stored? You can choose EU data residency. Data is encrypted at rest and in transit. ### Are you certified? Yes. CommerceClarity is ISO/IEC 27001 certified, so information security is run as an audited management system, not a set of good intentions. ### How do you handle access control? Role-based access with SSO/SAML, least-privilege internal controls, and a full audit trail. ### How do we delete our data? You can export or delete your data at any time, and set retention windows we honor. ### Can you fill in our security questionnaire? Yes. Send it over and we will complete it. ### How do we report a vulnerability? Email security@commerceclarity.com with what you found and how to reproduce it. We will confirm we have it and tell you what we do about it. ## Need documentation or more detail? Anything your security review needs and this page does not cover, ask us. [Contact us](mailto:security@commerceclarity.com) ## Entities - [ISO/IEC 27001](https://www.iso.org/standard/27001) · Thing, about - [General Data Protection Regulation](https://eur-lex.europa.eu/eli/reg/2016/679/oj) · Thing, about - [EU Artificial Intelligence Act](https://eur-lex.europa.eu/eli/reg/2024/1689/oj) · Thing, mentions ## Sources - [ISO/IEC 27001, information security management](https://www.iso.org/standard/27001) · ISO - [Regulation (EU) 2016/679, the General Data Protection Regulation](https://eur-lex.europa.eu/eli/reg/2016/679/oj) · EUR-Lex - [Regulation (EU) 2024/1689, the Artificial Intelligence Act](https://eur-lex.europa.eu/eli/reg/2024/1689/oj) · EUR-Lex - [AI Risk Management Framework](https://www.nist.gov/itl/ai-risk-management-framework) · NIST --- Canonical: https://commerceclarity.com/trust-center Every page of this site is available as markdown: append `.md` to its path. Index: /llms.txt