What is encrypted, who can see your data, what happens in an incident — and an explicit list of the things we do not claim.
A productivity service holds your business's correspondence and files. That deserves specifics you can check, not a wall of badges.
Yes. TLS 1.2 or better between servers, and HTTPS with HSTS for everything you touch in a browser. Mail to a receiving server that refuses TLS is the one exception, and that is the other server's choice, not ours.
Yes — stored mail and files are encrypted on disk, and backups are encrypted separately with their own credentials.
No. Server-side encryption is not end-to-end encryption, and we will not blur that line. If your threat model genuinely requires end-to-end, standard business email is the wrong tool and we will tell you so.
There is no standing access. Any support access requires a stated reason, is time-limited, notifies the account owner, and is written to an audit log that cannot be edited afterwards.
We state the hosting region in writing before you buy — including when the honest answer is that some of it is not in Canada. A vague answer here is a red flag from any vendor, us included.
Yes, in standard formats, at any time, including after cancellation. Cancelling does not hold your business records hostage.
Card details are entered on Stripe's own hosted page and never pass through ClearGlass systems. We never see, transmit or store a card number, CVC or expiry date. What we hold is an opaque token that lets Stripe charge the card — and cannot be used anywhere else.
Read this part carefully — it is the part most vendor security pages leave out.
If a competitor's security page contains none of these caveats, that is not evidence they are more secure. It is evidence they wrote a marketing page.
The 90-minute ClearGlass Cyber Risk Audit reviews what you are running today — email authentication, account access, backup and recovery, and the three things most likely to hurt a business your size — and gives you prioritised findings you can act on, whether or not you ever become a Workspace customer.
Payment is processed by Stripe on their hosted checkout. Price is in Canadian dollars and exclusive of applicable GST/HST, which is calculated at checkout from your billing address.
No. Mail and files are encrypted in transit and encrypted at rest on our storage, but ClearGlass operates the service and so the data is not end-to-end encrypted in the cryptographic sense. Any provider offering standard business email with server-side search and web access is in the same position, whether or not they say so.
We tell you the hosting region in writing before you purchase, and it is stated in the data processing addendum. We do not make a blanket data-residency claim on a marketing page, because the honest answer depends on the configuration.
Not at present, and we say so rather than implying otherwise. For customers who need a certified provider, that is a legitimate reason to choose someone else, and we will say that in the sales conversation.
We assess severity, notify affected customers within one hour for anything customer-affecting, mitigate, and publish a written post-mortem within five business days. If personal information may have been exposed, we run the PIPEDA breach assessment in parallel and report to the Privacy Commissioner where the threshold is met.
Yes, and we recommend it. MFA is available on every account on every plan at no extra cost.
Your data is retained for 30 days after cancellation so you can export it, then permanently deleted. You are told both dates in writing, and the export link is included in the cancellation confirmation.
Ask them before you buy. If the answer is one you will not like, we would rather you heard it now.