Clewed Security Statement

Effective Date: September 2026

At Clewed, safeguarding our customers' data, platform infrastructure, and privacy is our highest priority. We maintain a multi-layered security framework designed to protect sensitive information, maintain high platform availability, and comply with modern security standards.

1. Governance & Compliance Framework

  • Data Classification Standard: Clewed classifies platform data into three tiers (Confidential Personal, Confidential Commercial, and Public/Unrestricted), and access to each tier is limited according to its sensitivity.
  • Infrastructure Hosting: Core application servers and database environments are hosted in SOC 2 Type II and ISO 27001 certified data center facilities provided by Summit Hosting / HorizonIQ. Physical access to data centers is strictly restricted to authorized facility personnel and monitored 24/7.
  • Access Control & Least Privilege: Administrative access operates under the Principle of Least Privilege and Role-Based Access Control (RBAC). Multi-Factor Authentication (MFA) is required for access to hosting and infrastructure management consoles, and production infrastructure management is restricted to authorized engineering leads.

2. Technical & Application Security

  • Vulnerability Management: We review our code and third-party dependencies for security vulnerabilities and remediate identified issues prior to production release.
  • Secure Development Life Cycle (SDLC): All source code changes are tracked against tickets in version control (Git), developed in isolated environments, and tested in a staging environment before production deployment.

3. Financial & Payment Data Protection

  • Out-of-Scope Architecture: Clewed does not collect, process, or store raw credit card numbers, bank account details, or routing credentials on our database or server infrastructure.
  • Third-Party Payment Processing: Online payments and bank account connections are handled by PCI-DSS compliant third-party providers (such as PayPal and Plaid). Card and bank credentials are entered directly on the providers' own secure pages or widgets and never pass through our servers.

4. Encryption & Business Continuity

  • Data Encryption in Transit: All network traffic between client browsers and the platform is encrypted using Transport Layer Security (TLS 1.2 or higher) with standard HTTPS enforcement.
  • Data Encryption at Rest: Platform databases, sensitive application records, and backup repositories are encrypted at rest using industry-standard AES-256 encryption.
  • Backups & Recovery: Automated daily system and database backups are transferred to isolated secondary storage, maintaining a defined Recovery Point Objective (RPO) of less than 24 hours.

5. Vulnerability Disclosure Policy

We welcome reports from security researchers and users to help maintain platform safety. If you believe you have identified a vulnerability within Clewed's application or infrastructure, please disclose it to us responsibly.

Reporting Guidelines:

  • Submit findings directly to security@clewed.com.
  • Provide step-by-step instructions, logs, or proof-of-concept details to help our engineering team reproduce the issue.
  • Do not attempt to view, alter, or delete customer data, or interrupt platform availability (e.g., through volumetric DDoS testing or automated spam).
  • Allow our team a reasonable timeline to evaluate and address the issue prior to public disclosure.

6. Contact & Escalations

For questions regarding this Security Statement, enterprise compliance inquiries, or security disclosures, please contact: