Thomson Reuters CLEAR

CLEAR + Salesforce Integration Architecture Diagram


Overview

This integration ensures that users no longer need to switch between systems to access critical risk data. By embedding Thomson Reuters CLEAR functionality within Salesforce, organizations can automate due diligence processes, trigger alerts or case creation based on CLEAR results, and maintain full audit trails—all within a single platform. The integration uses REST API for real-time communication and supports role-based access controls to ensure secure data handling.


Supported Functionalities / Endpoints

The following endpoints and features are supported in the current integration.

  • Confirm ID Person and Business​

  • Risk-Inform Person and Business V3​

  • Court Search

  • Adverse Media

    • Sanctions

    • PEP

    • State Owned

  • Continuous Monitoring​ - Manage Monitoring List, Members and Sanction Data

  • Batch Alerts

  • Advance Case Management

System Architecture & Workflow

Salesforce - Thomson Reuters Clear Integration


  1. The user will log in to Salesforce using the credentials or single sign-on (if set up by the customer) and MFA(multi-factor authentication). If single sign-on is enabled, the Salesforce user can log in using either SSO flows (Service Provider or Identity Provider Initiated Flow). Customers can also apply additional security measures, such as IP Restriction, SSO-only users, IP Login Hours, and User Login Tracking.

  2. Once the user is validated( either using Salesforce credentials or San AML token), they will be authenticated and can use the functionality.

  3. The “CLEAR Checker” is a 100% native application on Salesforce; hence, the client’s Salesforce administrator will be able to control the following functionality -

    1. Who should see/use the application? SF Admins need to grant the app license and permission. This can be done using the setup menu( permission sets and grant app license functionality).

    2. Prevent Unauthorized Sites and Network Addresses—Before any callout can call an external site, that site must be registered on the Remote Site Settings page, or the callout will fail. Salesforce prevents calls to unauthorized network addresses. This control will ensure no traffic/data is transmitted using the Cloud Maven servers.

  4. The cloud maven code will run on the client’s salesforce instance and connect with the CLEAR platform using the SSL certification and client credentials. The data is transmitted using the HTTPS protocol, and all data in transit is encrypted using the TLS1.2+ protocol. Customers will directly order credit reports from Equifax servers.

  5. The Cloud Maven platform encrypts most sensitive fields, but customers can choose to encrypt the remaining data using Salesforce Shield.

Notes : Cloud Maven, Inc. doesn’t store or transmit data using “Cloud Maven’s” servers or infrastructure. All Client requests originate from the client Salesforce org to the CLEAR platform. We don’t have access to the client’s data in transit or at rest.

Data in transit is encrypted using the TLS 1.2+ protocol and SSL. Data in Salesforce can be encrypted using the Salesforce Shield product.