At ClearAccess, the security of your Organization and the privacy of its members and visitors are core product responsibilities. This guide describes the controls and boundaries the product is designed to provide; your Organization remains responsible for its policies, configured integrations, and access administration.
Data Protection
Encryption
- In transit: Application traffic is protected by the transport security provided by the deployed ClearAccess service.
- At rest: Stored data is handled by the configured ClearAccess persistence layer and its deployment controls. Contact us for the current infrastructure and retention details for your rollout.
Data Sovereignty
We understand the importance of where your data lives. ClearAccess leverages Cloudflare's global network, allowing us to keep data within specific regions to comply with local data protection laws (e.g., NDPR in Nigeria).
Privacy by Design
Minimal Data Collection
We only collect the data necessary to verify a visitor. We do not sell your resident or visitor data to third parties.
Access Control
Role-Based Access
ClearAccess enforces strict role boundaries. A Gate Operator does not receive broad member contact data, and an Organization Member cannot see another household's visitor history. See our Roles and Permissions guide for more.
Access Passes and admission
Guest Passes are constrained by their Organization, validity period, permitted Access Points, and configured use limits. ClearAccess evaluates those rules, but the Gate Operator makes the final physical admission decision and records it for review.
Resident Passes must not rely on a static personal QR code. The target assurance model uses short-lived, cryptographically verifiable credentials and can require a stronger passkey-backed challenge-response flow for restricted or high-risk access.
Offline verification
Offline Assisted Verification is a continuity workflow, not proof of fresh revocation or complete cross-gate replay prevention. The scanner must expose the snapshot freshness and queue a reviewable record for reconciliation. Stale, unknown, payment-dependent, revoked, flagged, and other high-risk cases require manual review rather than automatic admission.
Every action taken by an Organization Manager or Gate Operator must be attributable to a named operator session, Scanner Device, Organization, Access Point, and time.
Compliance and rollout responsibility
ClearAccess supports role boundaries, configurable workflows, and privacy-conscious data handling. Whether a deployment meets a specific legal or regulatory requirement depends on the Organization's purpose, configuration, vendors, and operating procedures. Obtain the appropriate legal and privacy review before enabling sensitive integrations or collecting additional personal data.