Security & compliance
Security overview
How Clovie protects your data, your keys and your agents' traffic, and the controls you have over them.
Clovie sits in the path of your AI traffic and holds your provider keys, so it is built to be trusted with both. This page summarizes the protections in place and the controls you have. Your account team can share detailed security documentation under NDA.
Your data is yours
- Separated from other customers. Every organization's data is kept isolated from every other organization's.
- Encrypted. Traffic to and from Clovie is encrypted in transit. Stored data is encrypted at rest, and provider keys get an extra layer of encryption on top.
- Kept where your rules require. Clovie SaaS stores data in the United States. If your rules require another location, or your own network, you can run Clovie yourself; see Choose SaaS or self-hosted.
- Kept only as long as you want. Organization administrators set how long request content and records are kept, and can redact sensitive content before it is stored.
Access to Clovie
- Single sign-on with SAML or OIDC, and the option to require it for everyone.
- SCIM provisioning so people are added and removed from your identity provider automatically.
- Multi-factor authentication, which administrators can require for every user.
- Roles that separate who can view, who can change agents and policies, and who can turn enforcement on.
Protecting agent traffic
- One key per agent. Agents never see your provider keys, and any agent's key can be rotated or revoked on its own.
- Monitor before enforce. Policies and budgets start in monitor mode and are promoted only after a simulation on your own traffic.
- Kill switches stop one agent, or all of them, immediately.
- Your choice when checks are unavailable. If a policy check cannot run for a moment, you decide whether traffic continues with an alert or is rejected.
A record of everything
- Every policy decision the gateway makes is recorded with the agent, the policy version, the decision and the reason.
- Sign-ins, role changes and administrative changes are recorded in a separate security audit log.
- You can export evidence packs for auditors, covering policy decisions, approvals and policy definitions, with checksums so the files can be verified later.
Self-hosted installs
When you run Clovie yourself, the licence is checked entirely inside your network, software images are signed so you can verify them before you run them, and you can keep secrets in the secret store you already use.
Report a vulnerability
If you believe you have found a security issue in Clovie, email hello@clovie.io. Please do not disclose it publicly until we have had a chance to fix it.