← Back to home

Security foundations

Controls we can explain and verify.

Clippy is still maturing. This page describes controls implemented in the product today and states clearly where formal assurance work remains.

Authentication and roles

Signed-in sessions are validated on the server. Organisation administration is restricted to Owner and Admin roles at both page and API boundaries.

Server-side secrets

Automation and internal API credentials are expected as server environment variables and are not sent to the browser.

Organisation boundaries

Application queries use the signed-in user's organisation membership. Database row policies remain part of the defence-in-depth model.

Operational visibility

Role-protected diagnostics report authentication, database, integration, AI-provider, and automation configuration status without displaying secret values.

Assurance status

Clippy does not currently claim SOC 2, ISO 27001, GDPR certification, Australian data residency, or completed third-party security audits. Certification and independent assessment will be published only after they are completed and can be evidenced.