Security
آخر تحديث: Not yet issued
يُنشر هذا المستند بالإنجليزية. النسخة الإنجليزية هي النسخة المعتمدة.
Hosting
The application runs on Amazon Web Services in the eu-central-1 region, Frankfurt, Germany. The database and authentication layer are provided by Supabase. DNS and network protection are provided by Cloudflare. The precise region of each sub-processor is listed on the Sub-processor List.
Encryption
All traffic to and from the platform is served over HTTPS with a certificate issued by Let’s Encrypt and renewed automatically. Database backups are encrypted before they are written. We have not independently verified the at-rest encryption configuration of the managed database, and will state it here once we have.
Workspace isolation
Each customer’s data is held in its own isolated workspace. Access is scoped by company at the data layer, so a query issued in one workspace cannot return another workspace’s rows. Row-level security is enforced on every table as a second line of defence behind the application’s own checks.
Access control
Access within a workspace is role-based. Each role carries an explicit capability set, and a role that does not hold a capability cannot perform the action, whether it is requested through the interface or directly against the API.
Backups
The database is backed up on an automated schedule and the backups are encrypted. Restores are documented in an internal runbook. Off-site replication of those backups is not yet in place; the backups are held on the same infrastructure as the platform.
What we do not claim
We hold no ISO 27001 certification, no SOC 2 report, and we have not commissioned an external penetration test. We would rather tell you that than imply otherwise. If your procurement process requires any of these, write to us and we will tell you honestly where we are.
Reporting a vulnerability
If you believe you have found a security issue, write to info@clavix360.app. Please give us a reasonable period to respond before disclosing it publicly.
