Our security pillars
Encryption everywhere
AES-256 at rest, TLS 1.3 in transit, and encrypted backups. Keys rotated on a documented schedule with hardware-backed storage.
Least-privilege access
Role-based access, SSO/SAML/OIDC, SCIM provisioning, MFA enforcement, and just-in-time production access reviewed quarterly.
Tenant isolation
Every customer's data is logically isolated with row-level security. Cross-tenant queries are structurally impossible.
Continuous monitoring
24/7 log aggregation, anomaly detection, and alerting. All administrative actions are immutably audit-logged.
Resilient infrastructure
Multi-region cloud hosting with automated failover, daily encrypted backups, and documented RTO/RPO targets.
Independent assurance
Regular third-party penetration tests, vulnerability scanning, and secure SDLC with mandatory code review.
Compliance & certifications
Clarivexa aligns to global standards and Africa-specific data protection regimes. We publish current status transparently — including where an audit is still in progress.
How we handle your data
Ownership. You own all data you and your team put into Clarivexa. We act as a data processor on your instructions.
AI training. Your evidence, policies, model metadata, and generated documents are never used to train Clarivexa or third-party AI models.
Data residency. Customer workspaces are hosted in secure cloud regions with documented transfer safeguards where applicable (SCCs, adequacy decisions, Kenya DPA compliant transfer mechanisms).
Retention & deletion. You can export or delete workspace data on demand. Immutable audit logs are retained for at least seven years to preserve inspection integrity.
Subprocessors
We use a small set of vetted providers for hosting, email, and AI inference. Each is reviewed for security posture, data-handling terms, and jurisdictional fit before onboarding.
| Provider | Purpose | Region |
|---|---|---|
| Amazon Web Services | Primary application hosting & storage | EU / US |
| Supabase | Managed database, auth, storage | EU |
| Cloudflare | Edge network, DDoS protection, WAF | Global |
| Resend | Transactional email delivery | EU / US |
| OpenAI / Google / Anthropic | AI model inference (no training on your data) | US / EU |
Incident response
Clarivexa maintains a documented incident response plan aligned with ISO 27035 and NIST SP 800-61. Confirmed incidents affecting customer data are notified without undue delay and within the timelines required by GDPR (Art. 33) and the Kenya Data Protection Act §43.
- · Security Whitepaper
- · Data Processing Agreement (DPA)
- · Penetration Test Summary
- · Business Continuity & DR Plan
We welcome coordinated disclosure from security researchers. Please email findings to our security team; we respond within one business day.
security@clarivexa.io