Architecture and isolation
CleanIQ runs on DigitalOcean and stores operational records in Supabase Postgres. Authorization is tenant-scoped and enforced server-side. Each connected CRM remains the system of record.
Encryption and secrets
Traffic is protected with HTTPS/TLS. Connector credentials are encrypted server-side before storage. Production secrets are managed outside source code. Authentication uses secure, HTTP-only cookies and server-tracked sessions.
Access and change protection
Role-based access, organization ownership checks, privileged-route protection, login controls, input validation, and rate limiting reduce unauthorized access. Material CRM changes use explicit approval gates unless an authorized customer enables a supported auto-execute rule.
Monitoring and accountability
CleanIQ records authentication, administrative, scan, approval, write-back, support, and security events where supported. Admin operational views surface connector, job, queue, and security health. Logs and alerts support investigation but do not guarantee detection of every event.
Payments and AI boundaries
Stripe processes payment-card details; CleanIQ stores billing identifiers and subscription state, not full card numbers. Calia receives limited, credential-free context through the OpenAI API, requests
store: false, and cannot bypass CleanIQ approval gates.Backup and recovery status
The CRM is the system of record, but CleanIQ also stores operational account, subscription, scan, audit, support, and assistant records. Production currently runs without point-in-time recovery or a verified database restore path. The managed-backup upgrade and isolated restore verification are stage-gated before onboarding the twenty-fifth paying customer. CleanIQ does not claim that control is complete today.
Customer responsibilities
Use unique credentials, apply least privilege to CRM tokens, review team access, verify proposed changes, maintain appropriate provider exports or recovery options, and report suspected compromise promptly.
Incident response
CleanIQ will investigate suspected security incidents, take reasonable containment and recovery steps, and notify affected customers where and within the time required by applicable law or contract. CleanIQ does not promise a universal notification deadline that could conflict with investigation, law-enforcement, or legal requirements.
Responsible vulnerability disclosure
Send security reports to [email protected] with the affected page, impact, and safe reproduction details. Do not access another customer’s data, disrupt service, use automated high-volume testing, extort, or publicly disclose an unresolved issue. Never email passwords, API keys, full card numbers, or other secrets. CleanIQ will acknowledge and triage good-faith reports but does not authorize testing beyond the scope it confirms in writing.
Security testing
CleanIQ performs automated testing and release controls. It will not claim annual penetration testing until an independent program is actually funded, completed, and evidenced.
