Legal
Security
Last updated: May 28, 2026
Infrastructure
Cliux runs on dedicated cloud infrastructure. Databases are backed up automatically every night and retained on a rolling window, and all data in transit is encrypted via TLS 1.2+.
Data Protection
Sensitive data at rest is encrypted using industry-standard algorithms. Database access is restricted to authorized personnel via role-based access controls and multi-factor authentication. API keys and secrets are hashed or stored in secure vaults.
Application Security
We follow secure development practices including code review, dependency scanning, and regular penetration testing. Authentication is handled by Clerk with industry-standard OAuth and session management. We monitor for anomalous activity and unauthorized access attempts.
Compliance
We align with GDPR, KVKK, and PCI DSS requirements for payment processing via Stripe. Enterprise customers may request security questionnaires and SOC 2 reports where available.
Responsible Disclosure
If you discover a security vulnerability, please report it responsibly to security@cliux.com. Do not publicly disclose issues before we have had a reasonable time to remediate. We appreciate coordinated disclosure and may acknowledge researchers who help keep Cliux secure.
Other legal documents