Trust Center
Our posture, stated plainly — including what isn't finished.
This page is the single place to see where ClientVerse security and privacy stand today. It states current maturity honestly, with scope. It will never show a badge we have not earned or imply a review that has not happened.
Implemented today
Controls currently in operation.
These controls are implemented in ClientVerse's own systems today — starting with this website and its intake pipeline, which are held to the same discipline we bring to client deployments.
- Hardened public intake
- Website submissions are validated server-side with strict schemas, size limits, bot honeypots, and database-enforced rate limiting. Requests are recorded transactionally before any third-party synchronization.
- Privacy-preserving abuse controls
- Rate limiting uses salted, hashed network identifiers — raw addresses are not stored for this purpose.
- Secret hygiene
- Credentials exist only in the deployment platform's encrypted environment configuration. None are committed to the repository, and exposure triggers rotation.
- Least-privilege boundaries
- Public endpoints never hold privileged credentials. Privileged operations run in authenticated background jobs with bearer-token authorization.
- Security headers
- Strict transport and content-protection headers are applied across the site, including frame denial and content-type protections.
- Redacted error handling
- Third-party integration failures are logged internally and never expose provider details, tokens, or customer data to the browser.
In progress
What is being built — and not yet claimed.
The following are active workstreams. Until each is complete and evidenced, we do not claim it.
- Formal certifications
- ClientVerse holds no formal security certifications today (for example SOC 2 or ISO 27001) and does not claim regulatory compliance it has not been assessed for. Certification work is planned to follow, not precede, pilot maturity.
- Hub Security Passport program
- The per-Hub identity, configuration, and custody record described on the AI Workforce Hub page is part of the Hub's controlled-pilot development.
- Industry-specific compliance reviews
- Deployments touching regulated data (for example health information) undergo per-deployment review with the client's own compliance requirements. No blanket claims are made.
- Third-party assessment
- Independent security review is planned as pilots mature; results will be summarized here with scope.
Data practices
What we collect on this website, and why.
- Contact submissions
- Name, email, optional phone, organization, and your message — used to respond to your request and retained under the terms in our Privacy Policy. We do not ask for sensitive personal information, and forms are designed not to collect it.
- Measurement
- Privacy-controlled usage analytics measure which pages and paths help visitors, with sensitive-field masking and consent controls where required. Details are disclosed in the Privacy Policy.
- No data resale
- Visitor and client data is not sold, and client operational data is never used to train systems for other clients.
Reporting
Found a security issue? Tell us directly.
Reports of vulnerabilities or suspected incidents in ClientVerse systems are welcomed and taken seriously. Write to support@clientverse.io with 'SECURITY' in the subject line. We will acknowledge receipt, investigate, and tell you honestly what we find. We ask that you avoid accessing data that is not yours and give us reasonable time to correct issues before public disclosure.
Bring us your security questionnaire.
Enterprise buyers and security partners can request current documentation, ask direct questions about the posture above, or arrange a review conversation with the team.