Policy / public record

Security statement

A candid description of Clavinci's hosted security model, shared responsibilities, and vulnerability reporting process.

Effective dateEffective on public launch

01

Security model

Clavinci is a company-operated hosted service. Local collectors capture the allowed structured event contract, and the service uses authenticated APIs, relational storage, encrypted transport, and controlled infrastructure.

Clavinci is responsible for operating and securing the hosted application stack. Customers remain responsible for authorized users, identity-provider configuration, connector credentials, workforce notices, and lawful use.

02

Data minimization

Collectors are designed to capture engineering telemetry without storing prompt bodies, assistant response bodies, source code, clipboard content, environment values, or secrets. Clavinci validates this boundary whenever collectors or connectors change.

Structured collection reduces unnecessary data transfer. Customers must still secure developer devices, connector credentials, identity systems, and any local collector state.

03

Authorization and governance

The product distinguishes aggregate and individual access. Direct-manager individual reads are intended to be auditable, skip-level reporting is aggregated, and privacy floors suppress small groups. Query-layer anti-metrics prevent several harmful interpretations.

Customers remain responsible for membership accuracy, role assignment, identity integration, review of audit records, and timely removal of access. Clavinci is responsible for enforcing the configured product controls in the hosted service.

04

Shared security responsibilities

Clavinci is responsible for TLS, service identities, protected secrets, encrypted storage, network controls, backups, monitoring, dependency updates, and incident response for the hosted application stack.

Customers are responsible for secure identity configuration, connector scopes, authorized users, endpoint security, and their own incident and offboarding processes. Current audit reports, service commitments, and security addenda must be confirmed in the commercial process.

05

Report a vulnerability

Send a concise report to the configured security contact with the affected component, reproduction steps, impact, and suggested mitigation. Encrypt sensitive details when a public key is provided.

Do not access data that is not yours, degrade availability, use social engineering, or publicly disclose an unresolved issue before a reasonable remediation period. The operator will acknowledge valid reports and coordinate next steps when contact details are available.

06

Current boundaries

Clavinci is commercial software. Product access, support, warranties, service commitments, and data-processing terms are defined only by the applicable customer agreement.

A launch review must confirm the production host, headers, dependency state, secret handling, backup process, monitoring, incident contacts, and supported versions before this statement is treated as final.