Trust & Legal

Security Overview

A factual overview of CleanIQ’s current safeguards. This is not a certification or guarantee.

Last updated: July 29, 2026

Architecture and isolation

CleanIQ runs on DigitalOcean and stores operational records in Supabase Postgres. Authorization is tenant-scoped and enforced server-side. Each connected CRM remains the system of record.

Encryption and secrets

Traffic is protected with HTTPS/TLS. Connector credentials are encrypted server-side before storage. Production secrets are managed outside source code. Authentication uses secure, HTTP-only cookies and server-tracked sessions.

Access and change protection

Role-based access, organization ownership checks, privileged-route protection, login controls, input validation, and rate limiting reduce unauthorized access. Material CRM changes use explicit approval gates unless an authorized customer enables a supported auto-execute rule.

Monitoring and accountability

CleanIQ records authentication, administrative, scan, approval, write-back, support, and security events where supported. Admin operational views surface connector, job, queue, and security health. Logs and alerts support investigation but do not guarantee detection of every event.

Payments and AI boundaries

Stripe processes payment-card details; CleanIQ stores billing identifiers and subscription state, not full card numbers. Calia receives limited, credential-free context through the OpenAI API, requests store: false, and cannot bypass CleanIQ approval gates.

Backup and recovery status

The CRM is the system of record, but CleanIQ also stores operational account, subscription, scan, audit, support, and assistant records. Production currently runs without point-in-time recovery or a verified database restore path. The managed-backup upgrade and isolated restore verification are stage-gated before onboarding the twenty-fifth paying customer. CleanIQ does not claim that control is complete today.

Customer responsibilities

Use unique credentials, apply least privilege to CRM tokens, review team access, verify proposed changes, maintain appropriate provider exports or recovery options, and report suspected compromise promptly.

Incident response

CleanIQ will investigate suspected security incidents, take reasonable containment and recovery steps, and notify affected customers where and within the time required by applicable law or contract. CleanIQ does not promise a universal notification deadline that could conflict with investigation, law-enforcement, or legal requirements.

Responsible vulnerability disclosure

Send security reports to [email protected] with the affected page, impact, and safe reproduction details. Do not access another customer’s data, disrupt service, use automated high-volume testing, extort, or publicly disclose an unresolved issue. Never email passwords, API keys, full card numbers, or other secrets. CleanIQ will acknowledge and triage good-faith reports but does not authorize testing beyond the scope it confirms in writing.

Security testing

CleanIQ performs automated testing and release controls. It will not claim annual penetration testing until an independent program is actually funded, completed, and evidenced.