Security & Data Protection Architecture
Independent contractors and hiring clients trust Clivora with their contracts, client communications, and financial ledgers. Here is how we engineer our infrastructure to safeguard your business.
PostgreSQL Row-Level Security (RLS)
Every database query is gated at the Postgres engine layer using strict tenant-isolated RLS policies. A freelancer or client can never query or inspect records belonging to another organization, regardless of client-side parameters.
AES-256 File Vault Encryption
Documents, NDAs, project attachments, and deliverables stored inside the Clivora File Vault are encrypted at rest using industry-standard AES-256 encryption. Signed URLs expire automatically to prevent unauthorized sharing.
Zero Plaintext Credentials & Modern Auth
Clivora never stores raw user passwords. Authentication is handled via PKCE-flow OAuth 2.0 and cryptographically salted argon2/bcrypt hashes. Multi-factor authentication (TOTP) is supported across all accounts.
Zero Payment Credential Retention
Credit card numbers, bank account secrets, and payout credentials never touch or traverse Clivora application servers. All transaction billing is delegated directly to PCI-DSS Level 1 certified processors (Stripe & Safepay).
Hardened HTTP Security Headers
Clivora enforces strict HSTS (Strict-Transport-Security: max-age=63072000), frame isolation (X-Frame-Options: DENY), Content-Type protection (nosniff), and cross-origin isolation across all web endpoints.
GDPR & CCPA Data Sovereignty
Users maintain complete ownership of their data. In accordance with GDPR Article 17 and CCPA, you can export your complete business ledger or permanently delete your account and all associated records with one click.
Vulnerability Disclosure & Security Audits
We take proactive measures to maintain platform integrity. If you are a security researcher and believe you have discovered a vulnerability, please report it to our engineering team at contact@clivora.io. We review all technical submissions promptly.