Data security

Compliance data is client data. This page states plainly how ClauseIQ protects it.

§ 01

Field-level encryption for identifiers

PAN, TAN, GSTIN and director DINs in entity records are encrypted with AES-256-GCM before they reach the database, with the key held only in the server environment — a database read alone cannot expose them.

§ 02

Organisation isolation

Every query is scoped to your organisation on the server, and database row-level security policies enforce the same boundary independently. Members see their organisation's register and no one else's.

§ 03

Encrypted in transit and at rest

All traffic is TLS. The database (hosted on Supabase) encrypts storage at rest, on top of the field-level layer for statutory identifiers.

§ 04

Your research is not training data

Queries are processed to generate your answer and stored only in your own history. We do not sell data or use your matters to train models.

§ 05

Access control

Sign-in via Google OAuth or verified email. Invites are bound to a specific email address; domain auto-join can only be claimed by an owner for their own verified company domain. Reminder recipients receive email only — they have no access to your data.

§ 06

Security audit log

Every sensitive action — entity record changes, invites, membership changes, settings — is written to an append-only, owner-visible audit log with actor and IP. Completions on the register record who filed, when, and with what notes.

§ 07

Hardened browser surface

A strict Content-Security-Policy confines scripts and network calls to known origins, alongside HSTS, frame denial, and referrer and permissions policies. Statutory identifiers are format-validated server-side before they are accepted, and sensitive endpoints are rate-limited against brute force.

§ 08

Revocable access

Invites can be revoked before acceptance, members can be removed by the owner, and the calendar feed's secret link can be rotated at any time — old links stop working immediately.

Security questions or disclosures: security@clauseiq.net