Your customers' data is our top priority
We don't just say 'secure' — we prove it. Enterprise-grade protection built from day one, so you can focus on growing your business.
Bank-level encryption
Your data is locked with AES-256 encryption — the same standard used by major banks and governments.
Secure connections everywhere
Every connection uses TLS 1.3 — no data travels unprotected, ever.
Automatic data cleanup
Conversation data is automatically deleted after 90 days. You control how long things stick around.
PIPEDA & GDPR compliant
Fully compliant with Canadian and European privacy laws. Data processing agreements available on request.
SOC 2 certification in progress
We're going through the gold-standard security audit. Expected completion Q3 2026.
Enterprise cloud infrastructure
Hosted on AWS in Canada with Cloudflare DDoS protection. Your data never leaves North America.
How we protect your data
Isolated network
All services run in private networks — no public internet access to your data.
Strict access control
Every team member uses hardware security keys. All access is logged and reviewed.
Continuous monitoring
Security scans run daily. Penetration tests conducted quarterly by independent experts.
24-hour incident response
If something goes wrong, we respond within 24 hours — no waiting, no excuses.
Who we work with
| Provider | Purpose | Location |
|---|---|---|
| AWS (Canada) | Infrastructure & compute | ca-central-1 |
| Stripe | Payment processing | United States |
| OpenAI | AI inference | United States |
| Resend | Transactional email | United States |
| Cloudflare | CDN & DDoS protection | Global |
| Sentry | Error monitoring | United States |
Found a security issue?
We appreciate responsible disclosures and will respond within 48 hours.
security@claivi.com