Clerk Security: How We Protect Your Users
Blog post from Clerk
Clerk is a security-focused authentication provider that has been SOC 2 Type 2 and HIPAA certified since May 2022. It has a track record of finding, patching, and disclosing vulnerabilities quickly and transparently, with five disclosed CVEs since 2024, none of which have been exploited according to public records. Clerk employs a secure-by-default architecture with features like short-lived session tokens, server-side verification, breached-password detection, and bot protection. Despite some reliability issues, including a series of outages in early 2026, Clerk maintains a 99.99% uptime SLA for enterprise customers and publishes detailed postmortems. While it does not hold ISO 27001 certification or offer regional data residency, it complies with GDPR/CCPA and has a public Vulnerability Disclosure Policy. Clerk's transparency in handling security incidents and outages is notable, with a fast response to vulnerabilities and a commitment to continuous improvement in its security practices.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.