Trust & Security

Trust & security, built in and stated plainly.

How CloviTek keeps your data safe — walled-off customer data, secure practices, and privacy-first handling across every build and business service. We describe what we actually do, and we're explicit about what's on the roadmap versus in place today.

At a glance

Where we stand today.

The short version — in place now, and what's still ahead.

Per-tenant
Isolation model
In transit & at rest
Encryption
24/7
Automated monitoring
On roadmap
SOC 2 & ISO 27001 certification
Security overview

Security posture, without the theatre.

We build and run software for founders, so your data — and your customers' data — sits at the center of how we operate. Below is our real posture: how data is handled, how tenants are isolated, who our subprocessors are, and where our compliance work actually stands. We say “aligned with” and “on roadmap” where that is the truth — we never claim a certification we don't hold.

How we protect data, layer by layer.

Every request passes through the same defensive layers, whether it's a customer login or an internal build script. No layer is skipped for convenience.

  • Edge: Cloudflare TLS termination and DDoS filtering before traffic reaches our servers
  • Application: authenticated, least-privilege access on every endpoint
  • Data: encryption at rest, per-tenant scoping, no cross-tenant reads
  • Secrets: a central vault — never hardcoded in code or repositories
Defense layerslive
EdgeTLS · DDoS filtering
🔑ApplicationAuthenticated · least-privilege
DataEncrypted · tenant-scoped
🔒SecretsCentral vault only
Isolation

Walled-off customer data — our strongest control.

Every customer's data lives in its own scoped lane. There is no shared or global data file that spans tenants.

New accounts start empty. Always.

Every endpoint is scoped to the signed-in user. A new account never inherits another customer's data, and there is no global data file any tenant can reach into.

  • Every request is scoped to the signed-in user
  • No shared or global data files across tenants
  • New accounts start with a clean, empty workspace
  • Cross-tenant access is not a configuration option — it doesn't exist in the code path
Access control

Least-privilege, by default.

Who can reach what, and how secrets are kept out of code.

Administrative access is limited and reviewed. Secrets live in a central store, never in a repository or a build script, and every layer below the top can only reach what it's scoped to.

Build pipeline

Every build passes a security gate before it ships.

Security isn't a one-time audit — it's enforced by process, on every build, before anything goes live.

1📝DefineSpec gateScope and requirements verified before build starts
2CheckVerification gateAutomated checks against the spec and live code
3🔒AuditSecurity auditUnauthenticated endpoints, hardcoded secrets, injection risks, open CORS
4DecideShip / no-shipA human is accountable at the gate before release
Data handling

Privacy, by default — not by request.

What happens to your data once it's in our systems.

Data handlingpolicy
Minimal collectionOnly what a build or service needs
🚫No shared trainingCustomer data isn't used to train shared models
📄DPA on requestA Data Processing Addendum for customers
Rights honoredAccess, correction, and deletion on request

GDPR & CCPA principles, applied.

We operate with GDPR and CCPA principles in mind for every platform we run — not just the ones with a legal mandate to. If you ask us to show, correct, or delete your data, we do.

  • Access, correction, and deletion available on request
  • Data collection scoped to what each service actually needs
  • No repurposing of customer data to train shared models
  • Data Processing Addendum available to customers on request
Incident response

Detect, triage, remediate, notify.

What happens when something goes wrong.

1
DetectAutomated monitoring watches health continuously
Automated
2
TriageAnomalies are escalated to a human, not left to self-resolve
Human
3
RemediateThe issue is investigated and fixed at the source
Owned
4
NotifyAffected customers are told what happened and what we did
Disclosed
Availability

Monitored around the clock.

How we watch for and communicate about downtime.

24/7 automated monitoring

Platforms are watched continuously by automated systems, not checked manually on a schedule.

📊

Public status page

We publish reliability against a status page rather than committing to a hard uptime number in marketing copy.

📜

Enterprise SLAs

Contractual availability commitments are offered at the enterprise tier, negotiated per engagement.

Subprocessors

Who we rely on, and why.

We use established infrastructure and service providers to deliver CloviTek. This is the core set and what each is used for.

AWS
Amazon Web ServicesHosting, storage (S3), and CDN delivery (CloudFront)US / EU
CF
CloudflareDNS, edge caching, TLS termination, and DDoS protectionGlobal edge
GC
Google CloudAI model APIs and OAuth authenticationUS
AI
Model providersLLM inference across multiple providersUS
$
Stripe / ChargebeeBilling and subscription managementUS / EU

This list reflects our core infrastructure. A current, complete subprocessor list is available to customers on request via the security contact below.

Compliance status

Clear about where we are.

We are early-stage and building our formal compliance program. We describe this accurately rather than displaying a badge we haven't earned.

Shipped
In place today
  • Encryption in transit (TLS) and at rest
  • Per-tenant data isolation on every platform
  • Centralized secrets vault — never in code
  • 24/7 automated monitoring
On the roadmap
Formal certification
  • SOC 2 certification
  • ISO 27001 certification

We model our controls on SOC 2 and ISO 27001 practices and intend to pursue formal certification as we grow. Until then, we will not claim to hold either — only that our practices are aligned with them.

Security contact

Responsible disclosure

Found a vulnerability, or have a security or privacy question? Reach the team directly and we'll respond. We welcome responsible disclosure.

[email protected]
FAQ

Questions we get asked

Your data is encrypted in transit and at rest, scoped to your own tenant, and never used to train shared models. Access is least-privilege and secrets are held in a central store, never in code.
Through walled-off customer data: every account is scoped to its own data, new accounts start empty, and every endpoint is scoped to the signed-in user. There are no global or shared data files across tenants.
We are early-stage and do not yet hold SOC 2 or ISO 27001 certification. Our practices are aligned with both, and formal certification is on our roadmap. We will never display a badge we haven't earned.
Every build passes a security gate before it ships — automated checks for unauthenticated endpoints, hardcoded secrets, injection risks, and open CORS — with a human accountable at the gate. Security is enforced by process, not assumed.
No. Data is shared only with the subprocessors required to run the platform — hosting, CDN, model inference, and billing — never sold, and never used to train shared models.
Automated monitoring flags anomalies and escalates them to a human. If an incident affects your data, we investigate, remediate, and notify affected customers directly.
Keep exploring

Related capabilities

Every practice above is enforced by the same composed engineering team.

Ready when you are

Have a security or privacy question?

Talk to us about how we'd handle your data. We'll walk you through isolation, subprocessors, and our compliance roadmap — plainly.

Start a project →