Securitytryclave.ai / security

Your data,
kept safe.

Clave handles sensitive information from your restaurants: sales, labor, costs, and access to the systems you run. We protect that information with customer-scoped analytics, encrypted credentials, and controlled access.

01Encryption
At rest
and in transit
02Uptime
99.5%
monthly target
03Audit
SOC 2
Type II in progress
04Incident notice
≤72h
no undue delay
→ What we do
01

Your data stays yours

You retain ownership of your data. Clave processes it to provide the service and carry out your authorized instructions, as described in your agreement and our Data Processing Agreement.

02

Separate analytical environments

Our isolated analytics service uses separate customer databases and customer-scoped access credentials. Automatically provisioned environments have a dedicated service identity, with isolated analytical compute and separate read and write permissions. Before activation, we check the database identity and the reader's access scope.

Related organizations in a configured customer hierarchy can share an analytical environment with scoped permissions. Account management, transactional features, and some ingestion and supporting services remain on shared infrastructure protected by tenant-aware access controls.

03

Credentials protected by managed encryption keys

For integrations using our credential-custody system, stored credentials are encrypted with tenant-specific keys managed separately from the encrypted data. Reading the stored encrypted record does not, by itself, give access to the password.

Authorized connector services can decrypt credentials when needed to connect to your systems.

04

Controlled support access

For supported integrations, your administrators can grant and revoke time-limited support access to a specific credential from the product. That access has a defined scope and expiry, and the disclosure workflow records access and outcomes.

Routine connector operation and authorized configuration use separate machine-access controls. A support permission window is not permanent access, and revoking it prevents new disclosures under that grant.

05

Encryption and limited access

Customer data is encrypted in transit and at rest. We use authenticated identities, role-based permissions, tenant-aware authorization, and database access controls. Access is limited to authorized people and services with a business need, with multi-factor authentication for privileged access.

06

AI data protection

We do not use your data or content to train, improve, or develop AI models. We configure model-training opt-outs and zero-data-retention options where available, and use commercially reasonable efforts to ensure upstream model providers do not use your content for training, as set out in our DPA.

Integration credentials are handled separately from analytical prompts. AI-assisted connection workflows use controlled credential injection and redaction to limit exposure of authentication material to model requests.

07

Monitoring, recovery, and response

We monitor our systems and maintain backups and documented incident-response and recovery procedures. Backup and recovery methods vary by service component. Our monthly uptime target is 99.5%.

If we become aware of a Security Incident covered by our DPA, we notify affected customers without undue delay and no later than 72 hours after becoming aware of it, as provided in the DPA.

08

Verify our practices

Our security program is monitored through Vanta. Our Trust Center currently identifies SOC 2 Type II as in progress; it is the place to check current audit status and request available security documentation.

Our Trust Center also maintains our subprocessor list, including each provider's location and processing function. Our DPA provides at least 10 business days' advance written notice of additions or replacements and a process for customers to object.

Trust Center

Want the
full picture?

Read our Data Processing Agreement for the contractual commitments, or visit our Trust Center for current security information and available documentation.

Security | Clave