Security model

Authority is derived on the server.

Clarivy combines identity, tenant isolation, least privilege, evidence integrity, reviewer accountability and bounded AI around every case.

Tenant and connector boundary

Authority is server-derived. Connectors do not choose tenants, rewrite policy or bypass audit lineage.

Secure document request loop

Evidence requests use approved templates, tenant-bound dispatch, a secure upload portal and delivery outbox status before case attachment review.

Control model

ControlProduct behaviourProduction evidence
IdentityBearer session or scoped service credential establishes the caller.Enterprise sign-in policy, MFA and access-review records
Tenant scopeThe API derives organization context; the browser cannot select another tenant.Cross-tenant denial tests and database RLS tests
Least privilegeRoles, use-case scopes and capabilities guard protected actions.Role matrix, periodic review and denied-action logs
Evidence integritySources, excerpts, timestamps, actors and hashes remain attached.Hash verification and artifact lifecycle records
Human oversightAI output is a proposal; material evidence and decisions require a named person.Model-run ledger and reviewer rationale
Replay safetyIdempotency and signed-event checks prevent duplicate effects.Retry, duplicate and stale-event tests
Audit lineageActions append rather than overwrite historical state.Exportable event chain and verification results

Shared responsibility

AreaClarivy providesCustomer confirms
Purpose and policyCase-bound purpose, legal basis and immutable workflow versions.Approved use cases, legal interpretation and prohibited uses.
Identity and accessRoles, server-derived tenant context and scoped credentials.Identity provider, MFA policy, joiner/mover/leaver process.
Data handlingRetention metadata, lineage and controlled evidence storage paths.Residency, retention, legal hold, deletion and export requirements.
AI providersProvider adapter, minimization, schema and citation validation.Approved provider, region, model, DPA and remote-processing permission.
ConnectorsSigned intake, replay protection and explicit event allowlists.Provider licence, credentials, field mapping and sandbox certification.
Incident responseProduct logs, evidence preservation and technical runbooks.Notification contacts, regulatory assessment and customer response process.

Security rules for evidence

  • The client cannot choose tenant, audit actor or storage path.
  • Every uploaded artifact receives a generated identifier and hash.
  • Public and regulatory claims require a reviewable source URL.
  • Connector events remain signals until mapped and reviewed.
  • Qdrant or vector retrieval is never the authoritative record.
  • Sensitive prompt and document bodies stay out of telemetry.
  • Secrets never enter workflow documents, Git or browser code.
  • Historical policy and review state is not silently rewritten.

Required before regulated production

GateRequired outcome
Enterprise authenticationOIDC or SAML SSO, MFA, provisioning and auditable access reviews.
Authoritative data isolationPostgreSQL row-level security and tenant-filtered retrieval.
Keys and encryptionManaged KMS, rotation, encrypted object storage and backup controls.
Document safetyMalware scanning, quarantine release and recipient verification.
Privacy operationsDPIA, processing inventory, rights handling, retention, deletion and legal hold.
Operational resilienceMonitoring, incident response, restore tests and agreed recovery objectives.
Customer acceptanceSecurity, privacy, legal and provider boundaries approved in contract.

No compliance certification by implication

Product controls support a customer’s governed process. They do not make Clarivy, a connector or an AI model automatically compliant with every regulator, jurisdiction or customer policy.

Continue reading

Deployment guidance

Map the control model to SaaS, private-cloud or on-premises infrastructure.