Clavis is built to protect the credentials you trust it with.
All stored credentials are encrypted using industry-standard, authenticated symmetric encryption. Encryption keys are managed separately from the database and are never stored alongside encrypted data.
All traffic to and from Clavis is encrypted via TLS/HTTPS.
Every access to a decrypted credential requires valid, non-revoked authentication and is recorded in an audit trail visible to you in your dashboard.
Clavis is hosted on DigitalOcean, in the NYC1 (United States) region.
We take automated, encrypted backups of our database every night. Local copies are kept for 14 days. An off-site encrypted copy is kept for disaster recovery and deleted after 30 days.
No system is perfectly secure. If we learn of a security incident affecting your account or your stored credentials, we will notify you by email without undue delay, and in any event within the time the law requires.