Security practices at Clearing include:
- HTTPS required on all pages, with HSTS to ensure browsers only ever connect over a secure connection
- Annual third-party penetration testing to check for vulnerabilities
- Passwords stored hashed with bcrypt; plaintext passwords are never stored or logged
- Two-factor authentication using time-based one-time passwords; authentication codes are never sent over insecure channels like SMS
- Full encryption of our database and all uploaded images
- Card numbers are never accessed or stored