CloviTek AICloviTekAI
Services ▾

Build

Web & Software
Full-stack web apps
AI & ML Engineering
Models, assistants, and automation
Mobile Apps
iOS and Android native
Cloud & DevOps
Infrastructure automated
Chatbots & Voice
Grounded AI assistants
Enterprise Search
Grounded enterprise search
Data & Analytics
Pipelines, warehouses, BI

Run Your Business

Finance & CFO
Bookkeeping and strategy
Branding & Creative
Identity and visual design
SEO & Content
Search visibility and copy
Marketing & Social
Growth and engagement
Security & Audits
Compliance and protection
Legal & Compliance Beta
Contracts and regulations
Sales & Outreach Beta
Pipeline and relationships

Delivery Models

Dedicated AI Team
Composed team full-time
Fractional CTO
Tech strategy governance
Staff Augmentation
Single expert role
Project Management
Gated delivery and QA
Operations

Get Your Startup HQ

A command center to run your AI business

Technologies ▾

AI

AI Models
A flexible multi-model layer
AI Assistants
Answers grounded in your own data

Product

Frontend
Next.js, React, Tailwind CSS
Backend
Node.js, Python, APIs
Mobile
Expo, React Native, iOS/Android

Data & Cloud

Data & Warehouses
Your data, organized
Cloud & DevOps
Reliable hosting & releases
Stack

Built on the models that fit

See our AI & engineering stack

Industries ▾

Verticals

Food & Agriculture
Agricultural tech platforms
Startups & SaaS
Fast-growing companies
All Industries
See our full portfolio
Vertical expertise
Vertical

Don't see your industry?

We adapt to any vertical, fast

How We Work ▾

The Process

Discovery
Define scope and plan
Build & Gate
Compose team and deliver
Verify
QA gates every step
Ship & Run
Launch and operate

How We Start

Discovery Sprint
Validate the scope
MVP Build
Ship core features fast
POC Development
Validate before building
Frontend/Backend Dev
Build user experience

Overview

How We Work
Full methodology
Process

See a real plan in ~90 seconds

Describe it — we compose the team

Our Work ▾

What We've Built

AI & Automation
Intelligent systems
Content & Media
Publishing platforms
Marketing & Sales
Growth tools
Analytics & Data
Intelligence systems
Developer & Security
Infrastructure tools
Finance & Strategy
Business platforms
Docs & Education
Learning tools
Plugins & Addons
Extensions

Portfolio

All Products We've Built
33 platforms total
Live Platforms
18 live today
See what we've built
Proof

18 live platforms, built on ourselves

Proof we build and run

Company ▾

Company

Our Story
How CloviTek started
Journey
The road we've travelled
Trust & Security
Security and compliance
Insights
Articles and learnings
Press
Press kit and media
Contact
Get in touch with us

The Engine

Our Fleet
The platforms we've built
The Brain
How the fleet thinks
Agents
The roles that build
Engineering
How we build and run

Investors

Investors
Our backing and vision
The Numbers
Metrics and traction
Financials
The books, transparently
Investor HQ
The data room
Mission

Founder-led, fleet-run

Build your company with us

Start a project
  1. Home
  2. ›
  3. Legal
  4. ›
  5. Security
Legal

Security Statement

Our general security posture and how to report a vulnerability. Written for transparency, without disclosing internal implementation detail.

Last updated 2026-07-22

On this page

  1. Overview
  2. Encryption
  3. Access controls
  4. Network & application
  5. Tenant isolation
  6. Monitoring & backups
  7. Standards
  8. Incident response
  9. Report a vulnerability
  10. Contact
Template notice. This document is a protective template provided for transparency and general information. It is not legal advice and is pending review by qualified legal counsel before final reliance. Where it conflicts with a signed agreement between you and CloviTek AI LLC, that agreement controls.

This Security Statement describes, at a general level, the technical and organisational measures CloviTek AI LLC uses to protect the data entrusted to us. To protect our systems and our customers, we describe our posture rather than internal implementation specifics.

1. Overview

We operate a layered security program covering encryption, access control, network protection, monitoring, and incident response. Security is built into how we design, build, and run our Services.

2. Encryption

We encrypt data in transit using TLS/HTTPS for data moving between you and our Services, and we apply encryption at rest for stored data where supported by the underlying platform. Credentials are stored hashed, and secrets are held in a secured vault and are never exposed in application outputs.

3. Access controls

Access to systems and data is restricted to personnel who need it to operate and support the Services, on a least-privilege basis, using role-based access controls. Administrative access is controlled and access is reviewed. We use per-account isolation so that access is scoped to the authenticated user.

4. Network and application protection

Our public services sit behind a content delivery network and web application firewall that provide DDoS mitigation and filtering of malicious traffic. We apply secure-development practices, input validation, and rate limiting, and we keep dependencies and platforms patched.

5. Tenant isolation

Each customer’s data is scoped and isolated to that customer’s account. A new account starts empty, access is scoped to the authenticated user, and one customer’s data is never pooled with or exposed to another. See our Data Handling page for more.

6. Monitoring and backups

We use logging and continuous monitoring to detect anomalies and to support investigation, and we maintain encrypted backups so we can recover from failure. Backups are not used to restore data a customer has asked us to delete.

7. Standards

Our security practices are aligned with recognised industry standards, including SOC 2 and ISO 27001 practices. Formal certification is on our roadmap; we do not claim to currently hold a certification we have not yet earned. Where payments are processed, card data is handled by our PCI-DSS-compliant payment providers (Stripe and Chargebee), and CloviTek AI does not store full payment-card numbers.

8. Incident response

We maintain an incident-response process to identify, contain, investigate, and remediate security incidents. Where a security incident affects your personal data and the law requires it, we will notify affected customers and, where applicable, the relevant authorities without undue delay, consistent with our Privacy Policy and any Data Processing Addendum.

9. Report a vulnerability

We welcome responsible disclosure. If you believe you have found a security vulnerability in our Services, please email [email protected] with the subject “Security — vulnerability report” and enough detail for us to reproduce it. Please do not publicly disclose the issue until we have had a reasonable opportunity to address it, and do not access, modify, or delete data that is not yours while testing.

10. Contact

For security questions or reports, email [email protected].

See also our Terms of Service, Privacy Policy, and full legal center.

Questions

For any question about this policy, reach us at [email protected] and we’ll respond promptly.

CloviTek AI LLC · 3731 S Broughtyferry Cv., Salt Lake City, UT 84106, USA · contact [email protected] · Last updated 2026-07-22. This page may be revised as our practices and services evolve; the date above always reflects the current version.

CloviTek AICloviTekAI

An autonomous AI company — we build and run the software and businesses founders need.

[email protected]
Build
Web & SoftwareAI & ML EngineeringMobile AppsCloud & DevOpsChatbots & VoiceEnterprise SearchData & Analytics
Run Your Business
Finance & CFOBranding & CreativeSEO & ContentMarketing & SocialSecurity & AuditsLegal & ComplianceSales & Outreach
Technologies
AI ModelsAI AssistantsFrontendBackendData & WarehousesCloud & DevOpsAll Technologies
Company
Our StoryOur FleetHow We WorkTrust & SecurityInvestorsInsightsPressContact
Industries & Work
Food & AgricultureStartups & SaaSAll IndustriesProducts We've BuiltLive Platforms
© 2026 CloviTek AI. All rights reserved.
Privacy PolicyTerms of ServiceCookiesDisclaimerData HandlingLegal Center
Security aligned with SOC 2 & ISO 27001 practices — certification on roadmap. Built on 19 live platforms, powered by 135+ AI agents.

We use cookies to run the site and understand how it's used. Choose what you're comfortable with.

Customise consent preferences

NecessaryAlways active

Required for basic features like secure log-in and saving your preferences. No personal data stored.

Functional

Enables sharing content on social platforms and collecting feedback.

Analytics

Helps us understand how visitors interact with the site — visits, bounce rate, sources.

Performance

Measures key performance metrics to deliver a better experience.

Advertisement

Used to tailor and measure advertising. Off by default.