Scorecard/Clutch Security

Clutch Security

Data gathering in process

Non-human identity security platform. Discovers, manages, and secures machine identities, API keys, and service accounts across cloud environments.

HQIL
Est2023
Size11-50
EU AI ActLimited Risk
clutch.security
Score
36.5 / 100
Evidence
3 items

Developing safety practices - core foundations in place with room for improvement.

Weaknesses:Governance Maturity, Technical Safety, Risk Assessment, Regulatory Readiness, External Engagement
Focus Areas
identity securitycloud securityapi securitymachine identity

Security Assessment

Security-relevant indicators for vendor evaluation

Security Posture
44
TS-01dim: 48
Red Teaming & Pre-deployment Testing
Adversarial testing before deployment
TS-05dim: 48
Robustness & Adversarial Resilience
Resistance to adversarial attacks
RA-01dim: 40
Sector-Specific Risk Assessment
Risk analysis for deployment context
RA-03dim: 40
Dual-Use & Misuse Risk
Dangerous capability awareness
RA-07dim: 40
Incident History & Track Record
Past incidents and response quality
EE-04dim: 20
Vulnerability Disclosure Program
Bug bounty or CVE reporting process
Incident History
Clutch Security incident records sourced from AIAAIC Repository and public reporting.
Integration: AIAAIC, OECD AI Incidents Monitor
Third-Party Audits
External audit reports, SOC 2 attestations, and ISO certifications verified where published.
Sources: Company filings, registry lookups
CVE & Disclosures
Known vulnerabilities and security advisories from NVD, GitHub Security Advisories, and vendor pages.
Sources: NVD, GHSA, vendor disclosure pages

Dimension Breakdown

GM
Governance Maturitymedium
Published policies, corporate structure, safety mandate, whistleblowing, executive commitment.
30
TS
Technical Safetymedium
Benchmarks, adversarial robustness, fine-tuning safety, watermarking, model cards, research output.
48
1 evidence items
TS-04
RA
Risk Assessmentlow
Dangerous capability evaluations, thresholds, external testing, bug bounty, halt conditions.
40
1 evidence items
RA-01
RR
Regulatory Readinesslow
ISO 42001, EU AI Act compliance, GPAI obligations, international commitments, incident reporting.
35
1 evidence items
RR-05
EE
External Engagementmedium
Survey participation, research support, transparency, behavior specs, open-source contributions.
20

Social Impact & Safety Profile

Emerging

Clutch Security provides identity and cloud security solutions. Their work is AI-adjacent with no published social impact policies specific to AI systems or their societal effects.

cloud securityidentity security

Need a detailed report for Clutch Security?

Subscribe to express interest in indicator-level evidence, peer benchmarking, and regulatory gap analysis - or reach out to request a full company overview brief.