Cloud-based services give organizations flexible, reliable access to the information and tools they need. They also make security an important business consideration; one study found that 28% of organizations experienced a cloud or SaaS related breach in the past year.
At Clarivate, security is embedded across our technology, programs and operational processes. We work to protect customer data, maintain reliable services and give you clear information about the safeguards that support the solutions you use.
You do not need to be a security specialist to understand our approach. The principles below explain how multiple safeguards work together to help reduce risk and what this means for your organization.
Security built in from the start
Security is considered throughout the lifecycle of Clarivate products and services – from architecture and design to development, deployment and ongoing operations.
Our teams follow secure development practices, conduct regular testing and reviews, address vulnerabilities through structured processes and monitor our environments for emerging threats. This integrated approach is designed to help protect customer data and support service reliability.
What you can expect
Layered protection
We use multiple security controls rather than relying on a single line of defense. These layers are designed to help prevent, detect and respond to threats. If one control is bypassed, others remain in place to help reduce risk.
Access based on need
Access to systems and information is managed according to role, business need and appropriate authorization. Limiting access to what is necessary helps reduce the risk of unauthorized activity or unnecessary exposure.
Identity and access verification
Modern security practices verify identity and permissions before granting access to resources. Measures such as multi-factor authentication can add another layer of protection at sign-in and help reduce the likelihood of unauthorized access.
Data safeguards
Clarivate applies technical and organizational measures to help protect information as it is stored, processed and shared. Applicable controls may include encryption, secure configuration and logical separation of customer data in multi-tenant environments.
Continuous monitoring and response
Monitoring and alerting help our security teams identify unusual activity and respond to potential events. Regular security reviews, vulnerability assessments and structured incident-response processes support ongoing resilience.
Security is a shared responsibility
Effective SaaS security depends on both the provider and the customer. Clarivate is responsible for the security of the services we operate. Customers also make important decisions about who can access their accounts, how permissions are configured and how information is shared within their organizations.
Practical steps such as reviewing user access, enabling available authentication controls and following your organization’s information-handling policies can help strengthen the safeguards built into the platform.
Our ongoing commitment
Security is not a one-time activity. As technology, threats and customer requirements evolve, we review and improve our controls, processes and practices.
By combining modern technologies, trained personnel, established security standards and independent assurance activities, we remain committed to maintaining a secure and trustworthy environment for our customers.
Learn more
Explore the Clarivate Trust Center, which brings together current information about our security, privacy and compliance practices, including certifications, statements and resources that can support your organization’s review.