Trust
Security at Cliently
We operate in your ad accounts, your CRM, and your revenue stack. Security isn't a feature — it's the foundation.
Encryption everywhere
All data is encrypted in transit (TLS 1.3) and at rest (AES-256). Tokens for connected ad accounts and CRMs are encrypted in a dedicated vault.
Least-privilege access
Row-level security on every Supabase table means users can only see their own organization's data. Admin actions are audited and role-gated.
PII hashing for attribution
Email and phone numbers sent to ad platforms via Conversion API are SHA-256 hashed on our servers before leaving — matching ad-platform specs without exposing raw PII.
Autopilot guardrails
ClientlyAI can only spend up to your configured daily cap. Any action above a dollar threshold you set requires explicit approval before it executes.
Signed audit trail
Every admin action, contract signature, and autopilot decision is recorded with actor, target, and timestamp for SOC 2-ready evidence.
Compliance
We follow GDPR, CCPA, and TCPA standards. SOC 2 Type II audit in progress. Security questionnaire available under NDA — email security@cliently.app.
Responsible disclosure
Found a vulnerability? Email security@cliently.app with reproduction steps. We respond within 24 hours and reward valid findings.