SOC 2 policies for Clerk teams
Clerk stores or processes customer data on your behalf, so it appears in the policies about access, encryption, backups, vendor risk and privacy, and in the vendor inventory those policies require.
Vendors and subprocessors · Referenced by 5 of 22 policies · Generator preset available
The 5 policies that reference Clerk
With Clerk in your intake, these policies name it in their scope, roles and procedures. The other 17 policies in the set apply to your company regardless of tooling; the template index lists all 22.
- P03 Access Control Policy: Defines how access to systems and data is requested, approved, provisioned, reviewed and removed.
- P04 Authentication and Password Policy: Sets the requirements for passwords, multi-factor authentication, sessions and secrets used by people and systems.
- P08 Encryption and Key Management Policy: Sets minimum encryption standards for data in transit and at rest and defines how cryptographic keys, secrets and certificates are generated, stored, rotated and retired.
- P16 Vendor and Third-Party Risk Management Policy: Requires vendors to be inventoried, tiered by the data and services they touch, assessed before onboarding, bound by contract, reviewed annually and offboarded cleanly.
- P22 Privacy and Data Protection Policy: Sets out how personal data handled through the product and the business is collected, used, shared, protected, retained and made available to the people it concerns.
What the Audit Kit writes for Clerk
The free generator fills in names. The Audit Kit goes further: Claude rewrites section 4 (Policy Statements) and section 5 (Procedures) of each policy using your full intake, so the text describes Clerk the way you actually run it. The statements below are examples of that output for Clerk; your own answers produce different text, and every statement should be checked against your configuration before management adopts it.
P03 Access Control Policy
Customer tenant access in the product is modelled with Clerk Organizations, membership roles and custom permissions are enforced on the server from the session claims rather than in client code, and the Clerk Dashboard is limited to named engineers with multi-factor authentication enabled on their Clerk accounts.
P04 Authentication and Password Policy
The production Clerk instance offers authenticator app (TOTP) and passkey second factors with SMS disabled, the application requires organisation administrators to complete second-factor enrolment before privileged actions by checking the user's two-factor status, compromised passwords are rejected using Clerk's breached-password check, and the minimum password length is 12 characters.
Clerk session lifetime is set to a seven-day maximum with a 24-hour inactivity timeout, and attack protection is enabled: bot sign-up protection, lockout after repeated failed sign-in attempts, and new-device verification that requires an email code the first time an account signs in from an unrecognised device.
P08 Encryption and Key Management Policy
Clerk hashes passwords with bcrypt and manages the session token signing keys, and the application verifies session tokens against Clerk's JWKS endpoint. The Clerk secret key and webhook signing secret are stored in the secrets manager, rotated when an engineer with access leaves, and never included in client bundles; only the publishable key is shipped to the browser.
P16 Vendor and Third-Party Risk Management Policy
Clerk is recorded in the vendor register as a Critical vendor for authentication. Its SOC 2 Type II report and data processing addendum are obtained and reviewed annually, the Clerk status page is subscribed to the incident channel, and the continuity plan documents the user export and migration path if the service has to be replaced.
P22 Privacy and Data Protection Policy
Clerk holds names, email addresses, phone numbers and sign-in metadata for product users and is listed as a subprocessor in the privacy notice. Deletion requests are executed through the Clerk Backend API and confirmed in the request ticket within 30 days, and access requests are fulfilled by exporting the user record through the same API.
How to use this page
- Open the generator with the Clerk preset and answer the remaining questions: company, product, headcount, other tools, data types, owners, scope and review cadence.
- Download the 22 policies as Markdown. Read the sections that mention Clerk with the admin console open and fix anything that is not true of your setup.
- Optionally buy the Audit Kit to have sections 4 and 5 tailored to Clerk and the rest of your stack, and to get Word documents, the TSC crosswalk, an evidence checklist, acknowledgment forms and a review calendar in one ZIP built on your machine.
- Have management approve the policies, collect acknowledgments, and start producing the evidence the procedures describe. The CPA firm performs the examination.
Other tools
Cloud platforms: AWS, Google Cloud, Microsoft Azure, Vercel, Cloudflare
Source control and CI: GitHub, GitLab
Identity providers: Google Workspace, Okta, Microsoft 365
Vendors and subprocessors: Supabase
Frequently asked questions
- Does Clerk's SOC 2 report cover our own SOC 2?
- No. Clerk's own SOC 2 report covers the controls Clerk operates for its platform. Your examination covers how your company configures and uses Clerk: who has access, how it is authenticated, what is logged and how data in it is protected. Auditors read the vendor's report to decide what they can rely on, and the Vendor and Third-Party Risk Management Policy tells you to collect it at onboarding and annually.
- What does the generator pre-fill when I arrive from this page?
- The link on this page opens the generator with a preset that adds Clerk to the vendor list. The other answers (company, product, headcount, owners, data types, scope and review cadence) are yours to fill in. The policies render in your browser as Markdown; nothing is sent to a server and there is no signup.
- Which policies change when I add Clerk to my answers?
- 5 policies name Clerk once it is in the intake: Access Control Policy, Authentication and Password Policy, Encryption and Key Management Policy, Vendor and Third-Party Risk Management Policy, Privacy and Data Protection Policy. The free generator names it in scope, roles and procedures; the Audit Kit ($39 one-time) rewrites sections 4 and 5 of each policy with statements specific to how Clerk is configured, like the examples on this page. Refunds are available within 14 days on request.
Policyseed provides governance policy templates and AI tailoring. It is not legal advice and not a compliance guarantee. Management adopts the policies; the CPA firm performs the SOC 2 examination.