ClearGlass Inc. CLARITY IS POWER← Home
ClearGlass Workspace

Security answers you can check, not badges you cannot.

What is encrypted, who can see your data, what happens in an incident — and an explicit list of the things we do not claim.

Straight answers, in the order people actually ask them

A productivity service holds your business's correspondence and files. That deserves specifics you can check, not a wall of badges.

Is it encrypted in transit?

Yes. TLS 1.2 or better between servers, and HTTPS with HSTS for everything you touch in a browser. Mail to a receiving server that refuses TLS is the one exception, and that is the other server's choice, not ours.

Is it encrypted at rest?

Yes — stored mail and files are encrypted on disk, and backups are encrypted separately with their own credentials.

Is it end-to-end encrypted?

No. Server-side encryption is not end-to-end encryption, and we will not blur that line. If your threat model genuinely requires end-to-end, standard business email is the wrong tool and we will tell you so.

Can staff read my mail?

There is no standing access. Any support access requires a stated reason, is time-limited, notifies the account owner, and is written to an audit log that cannot be edited afterwards.

Where is the data?

We state the hosting region in writing before you buy — including when the honest answer is that some of it is not in Canada. A vague answer here is a red flag from any vendor, us included.

Can I get my data out?

Yes, in standard formats, at any time, including after cancellation. Cancelling does not hold your business records hostage.

How accounts are protected

Payments: what we never hold

Card details are entered on Stripe's own hosted page and never pass through ClearGlass systems. We never see, transmit or store a card number, CVC or expiry date. What we hold is an opaque token that lets Stripe charge the card — and cannot be used anywhere else.

This is a deliberate architectural choice, not a policy statement. There is no field anywhere in our database that could hold a card number, which means no bug, no misconfiguration and no compromise of our systems can leak one.

What we do not claim

Read this part carefully — it is the part most vendor security pages leave out.

If a competitor's security page contains none of these caveats, that is not evidence they are more secure. It is evidence they wrote a marketing page.

Want the same scrutiny applied to your current setup?

The 90-minute ClearGlass Cyber Risk Audit reviews what you are running today — email authentication, account access, backup and recovery, and the three things most likely to hurt a business your size — and gives you prioritised findings you can act on, whether or not you ever become a Workspace customer.

Payment is processed by Stripe on their hosted checkout. Price is in Canadian dollars and exclusive of applicable GST/HST, which is calculated at checkout from your billing address.

Frequently asked questions

Is ClearGlass Workspace end-to-end encrypted?

No. Mail and files are encrypted in transit and encrypted at rest on our storage, but ClearGlass operates the service and so the data is not end-to-end encrypted in the cryptographic sense. Any provider offering standard business email with server-side search and web access is in the same position, whether or not they say so.

Where is my data stored?

We tell you the hosting region in writing before you purchase, and it is stated in the data processing addendum. We do not make a blanket data-residency claim on a marketing page, because the honest answer depends on the configuration.

Do you have SOC 2 or ISO 27001?

Not at present, and we say so rather than implying otherwise. For customers who need a certified provider, that is a legitimate reason to choose someone else, and we will say that in the sales conversation.

What happens if there is a security incident?

We assess severity, notify affected customers within one hour for anything customer-affecting, mitigate, and publish a written post-mortem within five business days. If personal information may have been exposed, we run the PIPEDA breach assessment in parallel and report to the Privacy Commissioner where the threshold is met.

Can I require MFA for everyone on my team?

Yes, and we recommend it. MFA is available on every account on every plan at no extra cost.

How long do you keep my data after I cancel?

Your data is retained for 30 days after cancellation so you can export it, then permanently deleted. You are told both dates in writing, and the export link is included in the cancellation confirmation.

Questions we have not answered here?

Ask them before you buy. If the answer is one you will not like, we would rather you heard it now.