Our general security posture and how to report a vulnerability. Written for transparency, without disclosing internal implementation detail.
This Security Statement describes, at a general level, the technical and organisational measures CloviTek AI LLC uses to protect the data entrusted to us. To protect our systems and our customers, we describe our posture rather than internal implementation specifics.
We operate a layered security program covering encryption, access control, network protection, monitoring, and incident response. Security is built into how we design, build, and run our Services.
We encrypt data in transit using TLS/HTTPS for data moving between you and our Services, and we apply encryption at rest for stored data where supported by the underlying platform. Credentials are stored hashed, and secrets are held in a secured vault and are never exposed in application outputs.
Access to systems and data is restricted to personnel who need it to operate and support the Services, on a least-privilege basis, using role-based access controls. Administrative access is controlled and access is reviewed. We use per-account isolation so that access is scoped to the authenticated user.
Our public services sit behind a content delivery network and web application firewall that provide DDoS mitigation and filtering of malicious traffic. We apply secure-development practices, input validation, and rate limiting, and we keep dependencies and platforms patched.
Each customer’s data is scoped and isolated to that customer’s account. A new account starts empty, access is scoped to the authenticated user, and one customer’s data is never pooled with or exposed to another. See our Data Handling page for more.
We use logging and continuous monitoring to detect anomalies and to support investigation, and we maintain encrypted backups so we can recover from failure. Backups are not used to restore data a customer has asked us to delete.
Our security practices are aligned with recognised industry standards, including SOC 2 and ISO 27001 practices. Formal certification is on our roadmap; we do not claim to currently hold a certification we have not yet earned. Where payments are processed, card data is handled by our PCI-DSS-compliant payment providers (Stripe and Chargebee), and CloviTek AI does not store full payment-card numbers.
We maintain an incident-response process to identify, contain, investigate, and remediate security incidents. Where a security incident affects your personal data and the law requires it, we will notify affected customers and, where applicable, the relevant authorities without undue delay, consistent with our Privacy Policy and any Data Processing Addendum.
We welcome responsible disclosure. If you believe you have found a security vulnerability in our Services, please email [email protected] with the subject “Security — vulnerability report” and enough detail for us to reproduce it. Please do not publicly disclose the issue until we have had a reasonable opportunity to address it, and do not access, modify, or delete data that is not yours while testing.
For security questions or reports, email [email protected].
See also our Terms of Service, Privacy Policy, and full legal center.
For any question about this policy, reach us at [email protected] and we’ll respond promptly.
CloviTek AI LLC · 3731 S Broughtyferry Cv., Salt Lake City, UT 84106, USA · contact [email protected] · Last updated 2026-07-22. This page may be revised as our practices and services evolve; the date above always reflects the current version.