Policy / public record
Security statement
A candid description of Clavinci's hosted security model, shared responsibilities, and vulnerability reporting process.
Effective dateEffective on public launch
01
Security model
Clavinci is a company-operated hosted service. Local collectors capture the allowed structured event contract, and the service uses authenticated APIs, relational storage, encrypted transport, and controlled infrastructure.
Clavinci is responsible for operating and securing the hosted application stack. Customers remain responsible for authorized users, identity-provider configuration, connector credentials, workforce notices, and lawful use.
02
Data minimization
Collectors are designed to capture engineering telemetry without storing prompt bodies, assistant response bodies, source code, clipboard content, environment values, or secrets. Clavinci validates this boundary whenever collectors or connectors change.
Structured collection reduces unnecessary data transfer. Customers must still secure developer devices, connector credentials, identity systems, and any local collector state.
04
Shared security responsibilities
Clavinci is responsible for TLS, service identities, protected secrets, encrypted storage, network controls, backups, monitoring, dependency updates, and incident response for the hosted application stack.
Customers are responsible for secure identity configuration, connector scopes, authorized users, endpoint security, and their own incident and offboarding processes. Current audit reports, service commitments, and security addenda must be confirmed in the commercial process.
05
Report a vulnerability
Send a concise report to the configured security contact with the affected component, reproduction steps, impact, and suggested mitigation. Encrypt sensitive details when a public key is provided.
Do not access data that is not yours, degrade availability, use social engineering, or publicly disclose an unresolved issue before a reasonable remediation period. The operator will acknowledge valid reports and coordinate next steps when contact details are available.
06
Current boundaries
Clavinci is commercial software. Product access, support, warranties, service commitments, and data-processing terms are defined only by the applicable customer agreement.
A launch review must confirm the production host, headers, dependency state, secret handling, backup process, monitoring, incident contacts, and supported versions before this statement is treated as final.