Security & Compliance
Protecting your data is our highest priority. Here's how we do it.
End-to-End Encrypted
All data in transit is encrypted using HTTPS/TLS. Voice data is encrypted at rest.
GDPR Compliant
We comply with GDPR privacy regulations and provide data processing agreements.
Hosted on Supabase
Built on PostgreSQL and AWS infrastructure with enterprise-grade security.
Regular Audits
We conduct regular security audits and penetration testing.
Encryption & Data Protection
In Transit: All communication with Cluso servers uses TLS 1.2+ encryption (HTTPS).
At Rest: Your survey data and voice recordings are encrypted using AES-256 encryption at rest in Supabase Storage.
Encryption Keys: Encryption keys are managed by Supabase and follow industry best practices.
Access Control
Authentication: We use Supabase Auth with secure session tokens.
Row-Level Security (RLS): All data is protected by PostgreSQL RLS policies, ensuring users can only access their own organization's data.
Multi-Tenant Isolation: Data is completely isolated between organizations.
Audit Logging: All data deletions are logged in an immutable audit trail.
Data Retention & Deletion
Soft Deletions: When you delete a survey, it's marked as deleted but retained for 30 days for recovery purposes.
Permanent Deletion: After 30 days, surveys are automatically purged from all systems.
Account Deletion: When you delete your account, all associated data is removed within 7 days.
Audio Deletion: Voice recordings are deleted when their parent survey is permanently deleted.
Compliance & Certifications
GDPR: Cluso is GDPR compliant. We can provide Data Processing Agreements for enterprise customers.
CCPA: We comply with California Consumer Privacy Act requirements.
HIPAA: Cluso is not HIPAA-compliant and should not be used for healthcare data.
SOC 2: Supabase (our infrastructure provider) is SOC 2 Type II certified.
Incident Response
If we discover a security breach, we will:
- Notify affected users within 48 hours
- Provide details of what data was accessed
- Recommend protective actions
- Conduct a thorough investigation
- Implement preventive measures
Report a Security Issue
If you discover a security vulnerability, please email us at security@cluso.ai instead of disclosing it publicly. We will acknowledge your report within 24 hours and work with you to resolve the issue.
Do not: Attempt unauthorized access, modify data, or exploit vulnerabilities for any reason.