Clear Street — Modernizing the brokerage ecosystem
Image

Trade alongside sophisticated institutions, family offices and algorithmic traders on Clear Street's new trading platform.

Learn more

Clear Street Trust Center

Our Approach to Security

At Clear Street, security is foundational to how we build and operate our platform. As a firm operating in highly regulated financial markets, we design our systems to be secure by design, with a focus on protecting client data, ensuring system integrity, and maintaining operational resilience.

Our approach is risk-driven and continuously evolving to address emerging threats and changing regulatory expectations.

Independent Validation and Compliance

Clear Street undergoes regular independent audits to validate the effectiveness of our security controls. We maintain a SOC 2 Type II report covering the Prime Brokerage Platform, which evaluates the design and operating effectiveness of controls over an extended period.

This assessment is performed by an independent third-party auditor and provides assurance that our controls are appropriately designed and operating effectively in alignment with industry-recognized trust criteria.

Security Program and Governance

We operate a formal, company-wide information security program led by a dedicated security team and overseen by security leadership.

Our Program Includes:

  • Defined security policies and procedures
  • Ongoing risk assessments and control evaluations
  • Board-level oversight of security and internal controls

These practices ensure our security program evolves alongside our business and the threat landscape.

Controls at a Glance

  • Identity & Access Management

  • Data Protection & Encryption

  • Infrastructure & Network Security

  • Application Security

  • Monitoring & Threat Detection

  • Vulnerability Management

  • Incident Response

  • Risk Management

  • Change Management

Core Security Practices

Core Security Practices

012345
  • Protecting Client Data

    We implement layered controls to protect sensitive and regulated data throughout its lifecycle, including encryption, access restrictions, and data classification.

  • Secure Infrastructure and Access Controls

    Our infrastructure is designed with layered protections across cloud and network environments, with strict access controls and continuous monitoring.

  • Secure Software Development

    Security is embedded into our development lifecycle through code review, automated scanning, and controlled deployment processes.

  • Monitoring and Incident Response

    We maintain continuous monitoring and a formal incident response capability to detect, investigate, and respond to potential threats.

  • Third Party Risk Management

    We assess vendors prior to onboarding and periodically thereafter to ensure they meet our security standards.

  • 0 1

    Protecting Client Data

    We implement layered controls to protect sensitive and regulated data throughout its lifecycle, including encryption, access restrictions, and data classification.

  • 0 2

    Secure Infrastructure and Access Controls

    Our infrastructure is designed with layered protections across cloud and network environments, with strict access controls and continuous monitoring.

  • 0 3

    Secure Software Development

    Security is embedded into our development lifecycle through code review, automated scanning, and controlled deployment processes.

  • 0 4

    Monitoring and Incident Response

    We maintain continuous monitoring and a formal incident response capability to detect, investigate, and respond to potential threats.

  • 0 5

    Third Party Risk Management

    We assess vendors prior to onboarding and periodically thereafter to ensure they meet our security standards.