Trust Center
Explore how Clarivate protects data, meets global standards and builds confidence through transparent security and compliance practices. Find clear, reliable information about our security programs, compliance standards and commitment to protecting customer data.
Security built into every Clarivate product
Security is a core requirement across the Clarivate product lifecycle. From architecture and design through development, deployment and ongoing operations, we apply consistent security standards and controls. Our teams follow secure development practices, perform regular testing and reviews, and address vulnerabilities in a structured and timely manner. We monitor our environments to detect and respond to emerging threats and continuously improve our defences’. This integrated approach helps protect customer data, maintain service reliability and ensure our products meet the expectations of a global, trust-driven community.
Our core commitment
The Clarivate Trust Center provides clear, reliable information about our security, privacy and compliance practices, helping you understand how we protect data and support trust in every interaction.
Product security
Clarivate embeds security from the earliest stages of system and product design, ensuring secure, reliable, and resilient solutions. Our “Security by Design” approach integrates threat modeling, secure architecture, and compliance into every phase of development. We follow an industry-standard Secure Software Development Lifecycle, including SAST/DAST testing, multi-level security reviews, and third-party assessments to identify and remediate vulnerabilities.
A 24×7 Security Operations Center monitors all environments via SIEM, correlating encrypted logs with threat intelligence for real-time detection. Clarivate maintains a robust Incident Response Framework with clear roles, escalation paths, and regulatory notification processes to ensure rapid containment, investigation, and customer protection in the event of an incident.
Documentation
Summary of standards
ISO certifications that demonstrate our commitment to security
Clarivate maintains internationally recognized ISO certifications that validate our security management practices and demonstrate our ongoing commitment to protecting customer data and operations.
ISO 27018
ISO 27032
ISO 22301
ISO 27701
ISO 27017
ISO 27001
Frequently asked questions about trust and security
Find clear answers to common questions about how Clarivate protects data, maintains compliance and supports transparency across our products and services.
You can find information about data security on Clarivate’s Trust Center by visiting Information Security – Clarivate.
You can visit Clarivate Security Compliance – Clarivate and navigate to the section on compliance and certifications.
To stay updated on Clarivate’s trust and security policies go to the new standard page, you can regularly visit our Trust Center on the Clarivate website.
To stay updated on Clarivate privacy policy go to Privacy center – Clarivate.
To report a security incident or vulnerability, please contact our security team immediately via our dedicated email address: Responsible Vulnerability Disclosure Program – Clarivate.
The Trust Center provides comprehensive resources and documentation regarding our compliance with various industry standards and regulations. Visit the Trust Center at Security Compliance – Clarivate for more information.
You can find Clarivate responsible disclosure policy in our Trust Center on the Clarivate website. The policy outlines the procedures for reporting security vulnerabilities and how we handle such reports. Visit the Trust Center at Information Security – Clarivate and look for the section dedicated to responsible disclosure.
Clarivate protects customer data using a layered security approach that covers people, processes, and technology. We design our products with security in mind, apply access controls, monitor systems, and test for weaknesses on a regular basis.
Our program aligns with recognized frameworks such as ISO 27001 and SOC 2. These standards require documented controls, independent audits, and continuous improvement. You can learn more in our Security Compliance hub.
LINK: Security Compliance hub.
All customer-facing security and privacy information is available in the Trust Center. It brings together our Information Security, Privacy Center, and Security Compliance pages in one place.
These pages explain how we protect data, how we handle personal information, and which standards guide our work. They are written for customers and partners who need clear, reliable answers.
Need more information?
For additional details or product-specific security documentation, please contact your Clarivate account representative, who will be happy to assist you.
Clarivate follows a defined incident response process. When a security issue is identified, we investigate, contain the risk, and take corrective action based on severity and impact.
We also support responsible reporting through our Responsible Disclosure program. This ensures issues are handled quickly and transparently. See Product Security for more details.
If you believe you have found a security issue, you can report it through our Responsible Disclosure program. This provides a clear and safe way to share concerns with our security team.
Every report is reviewed and handled according to our internal processes and industry standards such as ISO 27001. Reporting helps us protect all customers and continuously improve our security.
Clarivate’s security program is built on internationally recognized frameworks such as ISO 27001 and SOC 2. These standards guide how we manage risk, protect information, and operate secure systems across our platforms.
Specific certifications and reports may vary by product and environment. Customers can find clear, up-to-date information about applicable standards in our Security Compliance hub, including which services are covered and how to request documentation.