Security foundations
Controls we can explain and verify.
Clippy is still maturing. This page describes controls implemented in the product today and states clearly where formal assurance work remains.
Authentication and roles
Signed-in sessions are validated on the server. Organisation administration is restricted to Owner and Admin roles at both page and API boundaries.
Server-side secrets
Automation and internal API credentials are expected as server environment variables and are not sent to the browser.
Organisation boundaries
Application queries use the signed-in user's organisation membership. Database row policies remain part of the defence-in-depth model.
Operational visibility
Role-protected diagnostics report authentication, database, integration, AI-provider, and automation configuration status without displaying secret values.
Assurance status
Clippy does not currently claim SOC 2, ISO 27001, GDPR certification, Australian data residency, or completed third-party security audits. Certification and independent assessment will be published only after they are completed and can be evidenced.