We just raised our $1M pre-seed
Securitytryclave.ai / security

Your data,
kept safe.

Clave handles sensitive data for your restaurants: sales, labor, costs, and the logins to your operating platforms.

Here’s how we keep it safe.

01Encryption
AES‑256
TLS in transit
02Uptime
99.5%
monthly target
03Audit
SOC 2
Type II in progress
04Incident notice
≤72h
no undue delay
What we do
01

You own your data

Your data is yours. You keep ownership of everything you put into Clave and everything it produces, and we use it only to provide the service to you.

02

We don’t train AI on your data

We do not use your data or content to train, improve, or develop AI models. Our AI routing is configured with model-training opt-out and zero-data-retention where available, and we require the same of upstream model providers.

03

Encryption

Your data is encrypted in transit (TLS) and at rest (AES-256). Secrets and platform credentials are kept in a dedicated secrets manager and are never hardcoded.

04

Isolation & access

Clave is multi-tenant with strict per-customer isolation: row-level security, tenant-scoped queries, and no shared AI memory between customers. Internal access follows least-privilege, is protected by multi-factor authentication, and is reviewed regularly.

05

Protecting your platform logins

The credentials you connect (POS, delivery, accounting, and more) are stored in a dedicated secrets manager via scoped service accounts, encrypted, and never passed through AI prompts.

06

Reliable & monitored

We target 99.5% monthly uptime, back up data daily with point-in-time recovery, and continuously monitor our systems. If a security incident affects your data, we notify you without undue delay, within 72 hours.

07

Compliance

Our security program is continuously monitored through Vanta and is being audited for SOC 2 Type II by an independent third-party auditor. A report is available under NDA on request. We apply the CCPA to the personal data we handle.

08

Vendors & subprocessors

Every vendor that can access customer data is vetted before onboarding and reviewed at least annually. The current subprocessor list lives in our Trust Center, and we notify customers in advance of changes.

Trust Center

Want the
full picture?

Our Trust Center has the live subprocessor list, compliance docs, policies, security questionnaires, and where to send vulnerability reports.

Visit trust.tryclave.ai